Abuse Info
Windows
Step 1
Obtain CA certificate incl. private key Use Certify (2.0) to export all certificates in the local machine certificate store and identify the CA certificate by the name of the CA:Step 2
Forge certificate and obtain a TGT as targeted principal. Forge a certificate of a target principal:Linux
Step 1
Back up the CA certificate with the credentials of a user with admin access on the enterprise CA host using Certipy, and identify the CA certificate by the name of the CA.Step 2
Forge a certificate of a target principal:Step 3
Request a TGT for the targeted principal using the certificate against a given DC:Opsec Considerations
When an attacker abuses a privilege escalation or impersonation primitive that relies on this relationship, it will necessarily result in the issuance of a certificate. A copy of the issued certificate will be saved on the host that issued the certificate.Edge Schema
Source: ComputerDestination: Domain
Traversable: Yes