Not every certificate attack requires a misconfiguration. Certificates and their private keys already exist on hosts, in user and machine stores, and a valid authentication certificate is a durable credential: it is not invalidated by a password change and often lasts a year or more. Stealing one and authenticating with it (pass-the-certificate) is a clean lateral-movement and persistence primitive.
Stealing certificates#
- User and machine certificate stores: exportable certificates with their private keys can be dumped to PFX, from memory or the store, on a compromised host.
- DPAPI-protected keys: private keys are protected by DPAPI; with the user's master key (or the domain backup key) they decrypt offline.
- Machine certificates: a host's own certificate authenticates as the machine account, useful for silver tickets and RBCD.
# Mimikatz: export certificates and keys from the stores
crypto::capi & crypto::certificates /export
# Certipy: collect certificates and DPAPI-protected keys from a host
certipy cert -export ...
Pass-the-certificate#
A stolen or issued certificate authenticates two ways:
- PKINIT (Kerberos): exchange the certificate for a TGT, then move with the ticket:
certipy auth -pfx victim.pfx -dc-ip <dc> # PKINIT -> TGT (and NT hash via UnPAC)
gettgtpkinit.py -cert-pfx victim.pfx example.local/victim victim.ccache
- Schannel (LDAPS/HTTPS): bind to LDAP over TLS with the client certificate, useful where PKINIT is unavailable but Schannel mapping is enabled (ESC10):
certipy auth -pfx victim.pfx -ldap-shell -dc-ip <dc>
Recovering the NT hash#
PKINIT returns the account's NT hash alongside the TGT via UnPAC-the-hash, so a stolen certificate becomes a reusable hash, converting a time-limited certificate into a credential that drives pass-the-hash indefinitely.
Exploitation notes#
- A certificate survives the owner's password reset, so a stolen or attacker-enrolled certificate is persistence: it keeps authenticating until it expires or is revoked.
- Machine certificates authenticate as
HOST$and feed silver tickets and RBCD. - Enrolling a certificate for yourself now, while you have access, is a deliberate persistence move (certificate account persistence), independent of any ESC.
Tools#
- Certipy (
cert,auth,-ldap-shell): export, PKINIT, and Schannel authentication. - Mimikatz (
crypto::certificates): export certificates and keys from Windows stores. - PKINITtools: explicit PKINIT and UnPAC.
References#
- SpecterOps: Certified Pre-Owned (theft and persistence)
- The Hacker Recipes: pass the certificate