ADCS
Conditions of vulnerable certificate template which can be abused
Identify the ADCS service installation
Enumerate the templates configured
Enumerate the vulnerable templates
If the enrolleeSuppliesSubject is not not allowed for all domain users, it wont show up in vulnerable template and needs to enumerated seperately (ESC1)
List all certificates for local machine in certificate store
Export the certificate in PFX format
Use Mimikatz to export certificate in pfx format (default cert pass is mimikatz)
Request certificate for DA user using ESC1 technique, and save it as cert.pem
Convert cert.pem to cert.pfx format
Request TGT using pfx cerificate and inject into memory
Request certificate for EA user using ESC1 technique
Convert cert.pem to cert.pfx format
Request TGT using pfx cerificate and inject into memory
Last updated