certificate-theft.md (10043B)
1 --- 2 title: "AD CS Certificate Theft" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/active-directory-methodology/ad-certificates/certificate-theft.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/ad-certificates/certificate-theft.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # AD CS Certificate Theft 14 15 **This is a small summary of the Theft chapters of the awesome research from [https://www.specterops.io/assets/resources/Certified_Pre-Owned.pdf](https://www.specterops.io/assets/resources/Certified_Pre-Owned.pdf)**<sup>[[1]](#references)</sup> 16 17 ## What can I do with a certificate 18 19 Before checking how to steal the certificates here you have some info about how to find what the certificate is useful for: 20 21 ```bash 22 # Powershell 23 $CertPath = "C:\path\to\cert.pfx" 24 $CertPass = "P@ssw0rd" 25 $Cert = New-Object 26 System.Security.Cryptography.X509Certificates.X509Certificate2 @($CertPath, $CertPass) 27 $Cert.EnhancedKeyUsageList 28 29 # cmd 30 certutil.exe -dump -v cert.pfx 31 ``` 32 33 ## Exporting Certificates Using the Crypto APIs – THEFT1 34 35 In an **interactive desktop session**, extracting a user or machine certificate, along with the private key, can be easily done, particularly if the **private key is exportable**. This can be achieved by navigating to the certificate in `certmgr.msc`, right-clicking on it, and selecting `All Tasks → Export` to generate a password-protected .pfx file.<sup>[[1]](#references)</sup> 36 37 For a **programmatic approach**, tools such as the PowerShell `ExportPfxCertificate` cmdlet or projects like [TheWover’s CertStealer C# project](https://github.com/TheWover/CertStealer) are available. These utilize the **Microsoft CryptoAPI** (CAPI) or the Cryptography API: Next Generation (CNG) to interact with the certificate store. These APIs provide a range of cryptographic services, including those necessary for certificate storage and authentication. 38 39 However, if a private key is set as non-exportable, both CAPI and CNG will normally block the extraction of such certificates. To bypass this restriction, tools like **Mimikatz** can be employed. Mimikatz offers `crypto::capi` and `crypto::cng` commands to patch the respective APIs, allowing for the exportation of private keys. Specifically, `crypto::capi` patches the CAPI within the current process, while `crypto::cng` targets the memory of **lsass.exe** for patching. 40 41 ## User Certificate Theft via DPAPI – THEFT2 42 43 More info about DPAPI in: 44 45 46 [Dpapi Extracting Passwords](/hacktricks/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords) 47 48 In Windows, **certificate private keys are safeguarded by DPAPI**. It's crucial to recognize that the **storage locations for user and machine private keys** are distinct, and the file structures vary depending on the cryptographic API utilized by the operating system. **SharpDPAPI** is a tool that can navigate these differences automatically when decrypting the DPAPI blobs.<sup>[[1]](#references)</sup> 49 50 **User certificates** are predominantly housed in the registry under `HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates`, but some can also be found in the directory `%APPDATA%\Microsoft\SystemCertificates\My\Certificates`. The corresponding **private keys** for these certificates are typically stored in `%APPDATA%\Microsoft\Crypto\RSA\User SID\` for **CAPI** keys and `%APPDATA%\Microsoft\Crypto\Keys\` for **CNG** keys. 51 52 To **extract a certificate and its associated private key**, the process involves: 53 54 1. **Selecting the target certificate** from the user’s store and retrieving its key store name. 55 2. **Locating the required DPAPI masterkey** to decrypt the corresponding private key. 56 3. **Decrypting the private key** by utilizing the plaintext DPAPI masterkey. 57 58 For **acquiring the plaintext DPAPI masterkey**, the following approaches can be used: 59 60 ```bash 61 # With mimikatz, when running in the user's context 62 dpapi::masterkey /in:"C:\PATH\TO\KEY" /rpc 63 64 # With mimikatz, if the user's password is known 65 dpapi::masterkey /in:"C:\PATH\TO\KEY" /sid:accountSid /password:PASS 66 ``` 67 68 To streamline the decryption of masterkey files and private key files, the `certificates` command from [**SharpDPAPI**](https://github.com/GhostPack/SharpDPAPI) proves beneficial. It accepts `/pvk`, `/mkfile`, `/password`, or `{GUID}:KEY` as arguments to decrypt the private keys and linked certificates, subsequently generating a `.pem` file. 69 70 ```bash 71 # Decrypting using SharpDPAPI 72 SharpDPAPI.exe certificates /mkfile:C:\temp\mkeys.txt 73 74 # Converting .pem to .pfx 75 openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out cert.pfx 76 ``` 77 78 ## Machine Certificate Theft via DPAPI – THEFT3 79 80 Machine certificates stored by Windows in the registry at `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates` and the associated private keys located in `%ALLUSERSPROFILE%\Application Data\Microsoft\Crypto\RSA\MachineKeys` (for CAPI) and `%ALLUSERSPROFILE%\Application Data\Microsoft\Crypto\Keys` (for CNG) are encrypted using the machine's DPAPI master keys. These keys cannot be decrypted with the domain’s DPAPI backup key; instead, the **DPAPI_SYSTEM LSA secret**, which only the SYSTEM user can access, is required.<sup>[[1]](#references)</sup> 81 82 Manual decryption can be achieved by executing the `lsadump::secrets` command in **Mimikatz** to extract the DPAPI_SYSTEM LSA secret, and subsequently using this key to decrypt the machine masterkeys. Alternatively, Mimikatz’s `crypto::certificates /export /systemstore:LOCAL_MACHINE` command can be used after patching CAPI/CNG as previously described. 83 84 **SharpDPAPI** offers a more automated approach with its certificates command. When the `/machine` flag is used with elevated permissions, it escalates to SYSTEM, dumps the DPAPI_SYSTEM LSA secret, uses it to decrypt the machine DPAPI masterkeys, and then employs these plaintext keys as a lookup table to decrypt any machine certificate private keys. 85 86 ## Finding Certificate Files – THEFT4 87 88 Certificates are sometimes found directly within the filesystem, such as in file shares or the Downloads folder. The most commonly encountered types of certificate files targeted towards Windows environments are `.pfx` and `.p12` files. Though less frequently, files with extensions `.pkcs12` and `.pem` also appear. Additional noteworthy certificate-related file extensions include:<sup>[[1]](#references)</sup> 89 90 - `.key` for private keys, 91 - `.crt`/`.cer` for certificates only, 92 - `.csr` for Certificate Signing Requests, which do not contain certificates or private keys, 93 - `.jks`/`.keystore`/`.keys` for Java Keystores, which may hold certificates along with private keys utilized by Java applications. 94 95 These files can be searched for using PowerShell or the command prompt by looking for the mentioned extensions. 96 97 In cases where a PKCS#12 certificate file is found and it is protected by a password, the extraction of a hash is possible through the use of `pfx2john.py`, available at [fossies.org](https://fossies.org/dox/john-1.9.0-jumbo-1/pfx2john_8py_source.html). Subsequently, JohnTheRipper can be employed to attempt to crack the password. 98 99 ```bash 100 # Example command to search for certificate files in PowerShell 101 Get-ChildItem -Recurse -Path C:\Users\ -Include *.pfx, *.p12, *.pkcs12, *.pem, *.key, *.crt, *.cer, *.csr, *.jks, *.keystore, *.keys 102 103 # Example command to use pfx2john.py for extracting a hash from a PKCS#12 file 104 pfx2john.py certificate.pfx > hash.txt 105 106 # Command to crack the hash with JohnTheRipper 107 john --wordlist=passwords.txt hash.txt 108 ``` 109 110 ## NTLM Credential Theft via PKINIT – THEFT5 (UnPAC the hash) 111 112 The given content explains a method for NTLM credential theft via PKINIT, specifically through the theft method labeled as THEFT5. Here's a re-explanation in passive voice, with the content anonymized and summarized where applicable:<sup>[[1]](#references)</sup> 113 114 To support NTLM authentication `MS-NLMP` for applications that do not facilitate Kerberos authentication, the KDC is designed to return the user's NTLM one-way function (OWF) within the privilege attribute certificate (PAC), specifically in the `PAC_CREDENTIAL_INFO` buffer, when PKCA is utilized. Consequently, should an account authenticate and secure a Ticket-Granting Ticket (TGT) via PKINIT, a mechanism is inherently provided which enables the current host to extract the NTLM hash from the TGT to uphold legacy authentication protocols. This process entails the decryption of the `PAC_CREDENTIAL_DATA` structure, which is essentially an NDR serialized depiction of the NTLM plaintext. 115 116 The utility **Kekeo**, accessible at [https://github.com/gentilkiwi/kekeo](https://github.com/gentilkiwi/kekeo), is mentioned as capable of requesting a TGT containing this specific data, thereby facilitating the retrieval of the user's NTLM. The command utilized for this purpose is as follows: 117 118 ```bash 119 tgt::pac /caname:generic-DC-CA /subject:genericUser /castore:current_user /domain:domain.local 120 ``` 121 122 **`Rubeus`** can also get this information with the option **`asktgt [...] /getcredentials`**. 123 124 Additionally, it is noted that Kekeo can process smartcard-protected certificates, given the pin can be retrieved, with reference made to [https://github.com/CCob/PinSwipe](https://github.com/CCob/PinSwipe). The same capability is indicated to be supported by **Rubeus**, available at [https://github.com/GhostPack/Rubeus](https://github.com/GhostPack/Rubeus). 125 126 This explanation encapsulates the process and tools involved in NTLM credential theft via PKINIT, focusing on the retrieval of NTLM hashes through TGT obtained using PKINIT, and the utilities that facilitate this process. 127 128 ## References 129 130 - [1] [Certified Pre-Owned: Abusing Active Directory Certificate Services](https://www.specterops.io/assets/resources/Certified_Pre-Owned.pdf)