{"id":13845315,"url":"https://github.com/fortalice/modifyCertTemplate","last_synced_at":"2025-07-12T02:30:40.132Z","repository":{"id":39160889,"uuid":"440238664","full_name":"fortalice/modifyCertTemplate","owner":"fortalice","description":"ADCS cert template modification and ACL enumeration","archived":false,"fork":false,"pushed_at":"2023-06-26T14:14:34.000Z","size":30,"stargazers_count":126,"open_issues_count":2,"forks_count":12,"subscribers_count":2,"default_branch":"master","last_synced_at":"2024-08-05T17:44:18.258Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/fortalice.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2021-12-20T16:36:30.000Z","updated_at":"2024-06-06T09:19:53.000Z","dependencies_parsed_at":"2022-09-19T23:04:17.646Z","dependency_job_id":null,"html_url":"https://github.com/fortalice/modifyCertTemplate","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fortalice%2FmodifyCertTemplate","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fortalice%2FmodifyCertTemplate/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fortalice%2FmodifyCertTemplate/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fortalice%2FmodifyCertTemplate/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/fortalice","download_url":"https://codeload.github.com/fortalice/modifyCertTemplate/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":225784393,"owners_count":17523635,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T17:03:19.904Z","updated_at":"2024-11-21T18:31:08.421Z","avatar_url":"https://github.com/fortalice.png","language":"Python","funding_links":[],"categories":["Python"],"sub_categories":[],"readme":"# Purpose\nThis tool is designed to aid an operator in modifying ADCS certificate templates so that a created vulnerable state can be leveraged for privilege escalation (and then reset the template to its previous state afterwards). This is specifically designed for a scenario where `WriteProperty` rights over a template have been compromised, but the operator is unsure which properties the right applies to. In this scenairo, the template's ACL can be queried and the applicable ACE information can be cross-referenced with property GUIDs to determine the modifiable properties.\n\nAssociated [blog post](https://www.fortalicesolutions.com/posts/adcs-playing-with-esc4) on the tool and topic.\n\n# Usage\n```\nusage: modifyCertTemplate.py [-h] -template template name [-property property name] [-value new value] [-get-acl] [-dn distinguished name] [-raw] [-add flag name] [-debug]\n                             [-hashes LMHASH:NTHASH] [-no-pass] [-k] [-aesKey hex key] [-dc-ip ip address] [-ldaps]\n                             target\n\nModify the attributes of an Active Directory certificate template\n\npositional arguments:\n  target                [[domain/]username[:password]\n\noptional arguments:\n  -h, --help            show this help message and exit\n  -template template name\n                        Name of the target certificate template\n  -property property name\n                        Name of the target template property\n  -value new value      Value to set the specified template property to\n  -get-acl              Print the certificate's ACEs\n  -dn distinguished name\n                        Explicitly set the distinguished name of the certificate template\n  -raw                  Output the raw certificate template attributes\n  -add flag name        Add a flag to an attribute, maintaining the existing flags\n  -debug                Turn DEBUG output ON\n\nauthentication:\n  -hashes LMHASH:NTHASH\n                        NTLM hashes, format is LMHASH:NTHASH\n  -no-pass              don't ask for password (useful for -k)\n  -k                    Use Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on target parameters. If valid credentials cannot be found, it will\n                        use the ones specified in the command line\n  -aesKey hex key       AES key to use for Kerberos Authentication (128 or 256 bits)\n\nconnection:\n  -dc-ip ip address     IP Address of the domain controller. If omitted it will use the domain part (FQDN) specified in the target parameter\n  -ldaps                Use LDAPS instead of LDAP\n```\n# Examples\n### Querying a Template or Property Value\nQuery a certificate template (all attributes)\n```\npython3 modifyCertTemplate.py -template KerberosAuthentication ez.lab/administrator:pass\n```\n\nQuery a single attribute from a certificate template\n```\npython3 modifyCertTemplate.py -template KerberosAuthentication -property msPKI-Certificate-Name-Flag ez.lab/administrator:pass\n```\n\nQuery the raw values of all template attributes\n```\npython3 modifyCertTemplate.py -template KerberosAuthentication -raw ez.lab/administrator:pass\n```\n\n### Querying ACL Info\nQuery the ACL for a certificate template\n```\npython3 modifyCertTemplate.py -template KerberosAuthentication -get-acl ez.lab/administrator:pass\n```\nAlthough unrelated to certificate templates, any object's ACL can be queried by providing the object's distinguished name\n```\npython3 modifyCertTemplate.py -dn \"CN=ws1,CN=computers,DC=ez,DC=lab\" -get-acl ez.lab/administrator:pass\n```\n\n### Modifying a Template\nAdd the `ENROLLEE_SUPPLIES_SUBJECT` flag to the template's `msPKI-Certificate-Name-Flag` property\n```\npython3 modifyCertTemplate.py -template KerberosAuthentication -add enrollee_supplies_subject -property msPKI-Certificate-Name-Flag ez.lab/administrator:pass \n```\n\nUpdate the value of a certificate template attribute (non-list properties)\n```\npython3 modifyCertTemplate.py -template KerberosAuthentication -property msPKI-Certificate-Name-Flag -value -150994944 ez.lab/administrator:pass\n```\n\nAdd an EKU to the `pKIExtendedKeyUsage` property\n```\npython3 modifyCertTemplate.py -template KerberosAuthentication -add \"client authentication\" -property pKIExtendedKeyUsage ez.lab/administrator:pass \n```\n\nUpdate the value of a list-formatted attribute (i.e. explicitly set the value of `pKIExtendedKeyUsage`)\n```\npython3 modifyCertTemplate.py -template KerberosAuthentication -value \"'1.3.6.1.5.5.7.3.4', '1.3.6.1.5.5.7.3.2'\" -property pKIExtendedKeyUsage ez.lab/administrator:pass \n```\n\n# References, Credits and Other Projects to Check Out!\n- [PyWhisker](https://github.com/ShutdownRepo/pywhisker)\n- [Certi](https://github.com/zer1t0/certi)\n- [StandIn](https://github.com/FuzzySecurity/StandIn)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ffortalice%2FmodifyCertTemplate","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ffortalice%2FmodifyCertTemplate","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ffortalice%2FmodifyCertTemplate/lists"}