CertPotato – Using ADCS to privesc from virtual and network service accounts to local system
ID: 0869a467-ce4b-58d4-a26c-d544f4a5f497
STIX ID: report--0869a467-ce4b-58d4-a26c-d544f4a5f497
Feed Name: SensePost Blog
This post introduces “CertPotato,” a Windows/AD attack chain that leverages AD CS and Kerberos (PKINIT and TGT delegation) to escalate from service/virtual accounts to a machine account and ultimately NT AUTHORITY\SYSTEM. The author demonstrates obtaining a usable TGT, requesting a machine certificate to derive credentials, and forging a silver ticket for local SYSTEM access, then briefly discusses generated logs and defensive considerations such as hardening service accounts and restricting AD permissions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
