logo

CertPotato – Using ADCS to privesc from virtual and network service accounts to local system

ID: 0869a467-ce4b-58d4-a26c-d544f4a5f497

STIX ID: report--0869a467-ce4b-58d4-a26c-d544f4a5f497

Feed Name: SensePost Blog

Date Published: 2022-11-04

Date Updated: 2026-04-30

...
...

This post introduces “CertPotato,” a Windows/AD attack chain that leverages AD CS and Kerberos (PKINIT and TGT delegation) to escalate from service/virtual accounts to a machine account and ultimately NT AUTHORITY\SYSTEM. The author demonstrates obtaining a usable TGT, requesting a machine certificate to derive credentials, and forging a silver ticket for local SYSTEM access, then briefly discusses generated logs and defensive considerations such as hardening service accounts and restricting AD permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.