Abusing Active Directory Certificate Services (Part 4)
ID: dd8135be-70bd-5bea-bcd9-9a21342ce803
STIX ID: report--dd8135be-70bd-5bea-bcd9-9a21342ce803
Feed Name: Black Hills Infosec Blog
This blog post explains how misconfigurations in Active Directory Certificate Services (ADCS) — specifically overly permissive enrollment rights and insecure Extended Key Usage settings — enable ESC2 and ESC3 escalation techniques. Using Certipy, an attacker with a low-privilege account can request certificates (including Any Purpose or Certificate Request Agent templates), generate PFX files, request certificates on behalf of privileged accounts, extract Kerberos TGTs and NT hashes, and achieve persistent domain admin access. The article includes examples, commands, detection (event IDs) and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
