ADCS (Certificate Abuse) Commands
22 ADCS (Certificate Abuse) commands from the Credential Attacks category, each with its placeholders, supported authentication methods and upstream references.
Tools covered: bloodyAD, certipy
- bloodyAD Shadow Credentials Add a Key Credential (msDS-KeyCredentialLink) to a target object you have GenericWrite over. After this you…
- Certipy Account Operations Create, update, read, or delete user / computer accounts directly through Certipy. Particularly useful for…
- Certipy Authenticate with Certificate Authenticate using a PFX certificate to obtain a TGT and NT hash
- Certipy CA Management Enumerate and manipulate the certificate authority itself: list officers (ESC7), backup the CA private key,…
- Certipy ESC1 (Subject in Request) Exploit ESC1: a template that allows the requester to specify a Subject Alternative Name…
- Certipy ESC11 (RPC Relay to ICPR) ESC11: ICertPassage RPC interface accepts NTLM without IF_ENFORCEENCRYPTICERTREQUEST. Relay coerced…
- Certipy ESC13 (OID Group Link) ESC13: a template's issuance policy is linked to a privileged group via msDS-OIDToGroupLink. Enrolling adds…
- Certipy ESC14 (altSecurityIdentities Mapping) ESC14: weak explicit certificate mapping via altSecurityIdentities. With write access over a victim object,…
- Certipy ESC15 (Schema V1 EKUwu) ESC15 / EKUwu: schema v1 templates honor Application Policies from the CSR, letting an enrollee inject…
- Certipy ESC16 (CA Security Extension Disabled) ESC16: the CA has the szOID_NTDS_CA_SECURITY_EXT object identifier in DisableExtensionList, so issued…
- Certipy ESC2 (Any Purpose EKU) ESC2: template has the Any Purpose EKU (or no EKU at all), so the issued cert can be used for any purpose…
- Certipy ESC3 (Enrollment Agent) ESC3: a template has the Certificate Request Agent EKU. Get an enrollment-agent cert, then use it to enroll…
- Certipy ESC6 (EDITF_ATTRIBUTESUBJECTALTNAME2) ESC6: the CA has EDITF_ATTRIBUTESUBJECTALTNAME2 set, allowing any enrollee to specify an arbitrary SAN on…
- Certipy ESC7 (Vulnerable CA Access Rights) ESC7: you have ManageCA or ManageCertificates on the CA. Add yourself as an officer, approve a previously…
- Certipy ESC8 (HTTP Web Enrollment Relay) ESC8: AD CS Web Enrollment endpoint accepts NTLM and is missing EPA. Relay coerced machine authentication…
- Certipy ESC9 (No Security Extension) ESC9: certificate template has CT_FLAG_NO_SECURITY_EXTENSION, so the new szOID_NTDS_CA_SECURITY_EXT is not…
- Certipy Find Vulnerable Templates Enumerate ADCS certificate templates and identify vulnerable configurations
- Certipy Relay to ADCS Relay NTLM authentication to ADCS web enrollment to obtain a certificate
- Certipy Request Certificate Request a certificate from a vulnerable ADCS template
- Certipy Shadow Credentials Abuse shadow credentials to obtain a certificate for a target account
- Certipy Shadow Credentials (msDS-KeyCredentialLink) Abuse GenericAll/GenericWrite/WriteProperty over a target by writing a Key Credential to…
- Certipy Template Edit (ESC4) ESC4: when you have GenericWrite/WriteOwner over a template, rewrite its security descriptor / flags to make…