
HackTheBox - Certified
Source: YouTube · IppSec · published Mar 15, 2025 · 53:06
This video demonstrates an Active Directory Certificate Services (ADCS) attack chain on Hack The Box's "Breached" box, focusing on identifying high-value targets through certificate enrollment permissions.
Key Takeaways:
• The attacker begins by using certify to identify non-default users who can enroll for certificates, which helps pinpoint high-value targets for further enumeration 0:15.
• It is crucial to run certify without the -vulnerable flag initially to map all users with enrollment rights, rather than just checking against the current user's permissions 0:25.
• Mapping these non-default enrollment rights allows for better targeting when using BloodHound to analyze relationships and privilege escalation paths 0:36.
By correctly identifying enrollment permissions early, attackers can effectively narrow down their focus to specific users that offer the most significant privilege escalation opportunities in ADCD environments.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
what's going on YouTube this is IP doing certified from hack the box which is assumed to breach box meaning we start up with a set of credentials and you probably could guess based upon the name of this box it will involve active directory certificate Services AKA adcs so we start out by running certify and identifying the non-default users that can enroll certificates which is a great place to start thinking about an attack chain a lot of people that run certifi will just do the- vulnerable flag to see what um certificate templates are vulnerable to the user they're running it as but if you leave that flag out you can identify all the users that can roll things and looking at non default is a great way to identify high value targets which helps when you go into blood hound and map everyth…