Forward from: 1N73LL1G3NC3
Pwning the Domain: AD CS (Active Directory Certificate Services)
Domain Escalation:
• ESC 1 (Template misconfiguration)
• ESC 2 (Template misconfiguration)
• ESC 3 (Template misconfiguration)
• ESC 4 (Access Controls Attacks)
• ESC 5 (Sufficient rights against several objects)
• ESC 6 (CA Configuration)
• ESC 7 (Sufficient rights against the CA)
• ESC8
• ESC9
• ESC10
• ESC11
• ESC12
• ESC13
Domain Persistence:
• DPERSIST1 (Forge certificates with stolen CA certificate)
• DPERSIST2
• DPERSIST3
Account Persistence:
• PERSIST1 (User Account)
• PERSIST2 (Machine account)
• PERSIST3
Domain Certificate Theft:
• THEFT1 (Export user certificates with Crypto APIs)
• THEFT2 (Certificate theft via DPAPI): User certificates THEFT, Machine certificates Theft
• THEFT3
• THEFT4
• THEFT5
Domain Escalation:
• ESC 1 (Template misconfiguration)
• ESC 2 (Template misconfiguration)
• ESC 3 (Template misconfiguration)
• ESC 4 (Access Controls Attacks)
• ESC 5 (Sufficient rights against several objects)
• ESC 6 (CA Configuration)
• ESC 7 (Sufficient rights against the CA)
• ESC8
• ESC9
• ESC10
• ESC11
• ESC12
• ESC13
Domain Persistence:
• DPERSIST1 (Forge certificates with stolen CA certificate)
• DPERSIST2
• DPERSIST3
Account Persistence:
• PERSIST1 (User Account)
• PERSIST2 (Machine account)
• PERSIST3
Domain Certificate Theft:
• THEFT1 (Export user certificates with Crypto APIs)
• THEFT2 (Certificate theft via DPAPI): User certificates THEFT, Machine certificates Theft
• THEFT3
• THEFT4
• THEFT5