Skip to content

Certipy Attacks

Active Directory Certificate Services (AD CS) provides a critical infrastructure for managing digital certificates within a domain. Certipy is a powerful Python tool designed to interact with AD CS, enabling red teams to request and exploit certificates for Kerberos impersonation. This section demonstrates how to use Certipy to leverage certificate-based attacks, focusing on the process of requesting certificates and exploiting them for privilege escalation or lateral movement.


Certipy Overview

Certipy is part of the Impacket suite and simplifies interactions with AD CS by abstracting complex protocols like LDAP and Kerberos. It allows attackers to:
- Request certificates from a Certificate Authority (CA).
- Exploit certificates for Kerberos impersonation.
- Enumerate certificate templates and their permissions.

Certipy is particularly useful when targeting domains where certificate templates are misconfigured (e.g., allowing certificate enrollment without proper restrictions).


Requesting Certificates

To request a certificate, Certipy uses the request subcommand. This requires:
- A domain controller (DC) IP address.
- A user account with permissions to request certificates.
- A certificate template (e.g., User, Server, or CodeSigning).

Example: Requesting a User Certificate

certipy request --dc 10.10.10.1 --user user@DOMAIN --target DOMAIN --template User
This command requests a certificate using the User template. The output includes the certificate file (e.g., cert.pem) and the private key.

Key Notes:
- The requesting user must have permissions to enroll in the specified template.
- Certificates are issued by the CA and trusted by domain-joined machines.


Exploiting Certificates for Kerberos Impersonation

Once a certificate is obtained, it can be used to request a Kerberos Ticket Granting Ticket (TGT) for impersonation. Certipy’s kerberos subcommand automates this process.

Example: Requesting a TGT with a Certificate

certipy kerberos --dc 10.10.10.1 --user user@DOMAIN --target DOMAIN --certificate cert.pem
This command uses the previously requested certificate to impersonate a domain user. The output includes a .kirbi file containing the TGT.

Post-Exploitation:
- The .kirbi file can be decrypted with klist or used with tools like kerberos_ticket to access domain resources (e.g., file shares, services).
- The attacker can now act as the impersonated user, enabling lateral movement or privilege escalation.


Key Takeaways

  • Certipy simplifies AD CS exploitation by automating certificate requests and Kerberos impersonation.
  • Certificate templates must be misconfigured (e.g., overly permissive) for this attack to succeed.
  • Always validate certificate trust chains and enforce strict access controls on AD CS templates.
  • Mitigate risks by restricting certificate enrollment permissions and monitoring template usage.