Certipy is an open-source, Python-based security assessment and exploitation tool for Active Directory and Active Directory Certificate Services (AD CS). It is a dual-use utility rather than a distinct malware family. Its functionality includes Active Directory discovery, certificate-template enumeration, identification of exploitable certificate configurations, certificate-based authentication, relay operations, and shadow credential abuse. It can identify ESC1 template misconfigurations that enable certificate requests impersonating privileged accounts, supporting privilege escalation. It also supports exporting discovery results for BloodHound analysis.
Threat actors use Certipy during post-compromise operations to collect directory, credential, and certificate information and abuse domain authentication infrastructure. APT28, also known as Forest Blizzard and associated with Russia’s GRU Unit 26165, has used it alongside ADExplorer to harvest and exfiltrate directory data in campaigns targeting Western logistics and technology organizations supporting Ukraine. Operators installed Python on compromised Windows hosts to execute the tool. UAT-8837 has also deployed Certipy for Active Directory discovery and abuse during intrusions targeting North American critical infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The reported noPac fallback used CVE-2021-42278 and CVE-2021-42287 to request a ticket-granting ticket through the PaperCut server's domain computer account, impersonate the domain controller, and forge a high-privilege service ticket.
Where LSASS memory dumping failed, agents reportedly fell back to the noPac vulnerabilities, CVE-2021-42278 and CVE-2021-42287, using Rubeus or Certipy to obtain and forge high-privilege Kerberos tickets.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
After dumping the NTDS.dit, GRU’s operators employed two key tools, ADExplorer and Certipy, to harvest and exfiltrate directory data. They also installed Python on compromised hosts to run Certipy.
"Certipy identifies misconfigured certificate templates (ESC1). Certificate request submitted for Domain Admin."
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Finally, I authenticated using the issued certificate... Authentication succeeded, allowing me to impersonate the Domain Administrator without ever knowing the Administrator’s password.
Add Shadow Credentials Same as before, we’ll create shadow credentials using Certipy: certipy-ad shadow auto ... Adding shadow creds to james account | Modify the UPN ... we’ll set it to a DC machine account — in this case, LAB-DC.LAB.LOCAL for Schannel certificate-based authentication. certipy-ad account update ... -upn 'lab-dc$@lab.local'
By default, most Active Directory domains allow authenticated users to create up to ten computer accounts. The exploit takes advantage of this default configuration by creating a machine account that the attacker legitimately owns.
Where memory dumping came up empty, the agent fell back to the noPac vulnerabilities, CVE-2021-42278 and CVE-2021-42287. | “Where memory dumping came up empty, the agent fell back to the noPac vulnerabilities, CVE-2021-42278 and CVE-2021-42287.”
Finally, I authenticated using the issued certificate... Authentication succeeded, allowing me to impersonate the Domain Administrator without ever knowing the Administrator’s password.
Add Shadow Credentials Same as before, we’ll create shadow credentials using Certipy: certipy-ad shadow auto ... Adding shadow creds to james account | Modify the UPN ... we’ll set it to a DC machine account — in this case, LAB-DC.LAB.LOCAL for Schannel certificate-based authentication. certipy-ad account update ... -upn 'lab-dc$@lab.local'
This method relies on the ability to obtain the user’s NTLM hash using the PKINIT mechanism... Got NT hash for 'administrator@contoso.com'
Once operating as a Domain Controller, the attacker inherits one of the most sensitive privileges within Active Directory: directory replication. That privilege enables DCSync, a technique that requests password data directly through the Directory Replication Service Remote Protocol rather than reading the NTDS database from disk.
Instead of first validating the destination, the CA attempted to communicate with the supplied host using SMB and LDAP. That design decision created the opportunity for attackers to position themselves directly inside the enrollment workflow.
If the certificate template lacks the required security extension (objectSid), and we control a user account, we can manipulate its attributes to request a certificate that gets mapped to a different identity, like a DA.
«ESC8 (NTLM relay на HTTP enrollment endpoint) работает даже с непривилегированной учётной записью»
Once that certificate has been issued, it can be used with Kerberos PKINIT authentication to obtain Domain Controller credentials, enabling DCSync attacks that expose the krbtgt account and effectively hand over control of the domain.
“[The agent] exploited the S4U2self flaw to impersonate the domain controller, and forged a high-privilege service ticket.”
If an attacker obtains the krbtgt secret, they can forge Kerberos tickets that are trusted by every Domain Controller in the forest until the account password is reset appropriately. | Under specific deployment conditions, the CA can be convinced to issue a certificate containing the identity of a legitimate Domain Controller even though the request originated from an attacker-controlled machine.
Step 1 — Enumerate AD CS First, I looked for vulnerable certificate templates using Certipy.
Python scripts ... ensure [tasks] have actually completed. These include tasks like administrator access, account verification, Active Directory collection, domain and network discovery.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Active Directory Certificate Services enumeration and abuse tool used to identify an ESC1 certificate-template misconfiguration and request a certificate enabling Domain Admin impersonation.
An AD CS enumeration/abuse tool used to collect certificate-related data and facilitate credential access via certificate services misconfigurations.
A tool used for Active Directory discovery and abuse, particularly in certificate services contexts.
Tool for enumerating and abusing AD CS misconfigurations to escalate privileges and obtain persistence via certificate-based attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.