Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Certighost-CVE-2026-54121 — Splunk detection writeup for CVE-2026-54121 (CertiGhost): AD CS certificate chase abuse leading to full domain compromise. Lab-validated detection, triage steps, and incident investigation against a live DC. | Kitploit
工具/GitHubGitHub/atlasvector/certighost-cve-2026-54121
Authentication & AuthorizationDefensive ToolsVulnerability AnalysisIntrusion DetectionIncident ResponseLog Analysis
GitHubatlasvector/certighost-cve-2026-54121

Certighost-CVE-2026-54121

Splunk detection writeup for CVE-2026-54121 (CertiGhost): AD CS certificate chase abuse leading to full domain compromise. Lab-validated detection, triage steps, and incident investigation against a live DC.

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库
222个月前尚未审核
内容在请求的语言中不可用。显示英文版本。

Document Type: Detection Use Case Related CVE: CVE-2026-54121 (Certighost) Author: Youssef Benchater

Detection Use Case: Certighost (CVE-2026-54121)

This document describes the Splunk detection built for CVE-2026-54121. It follows the standard detection use case format so it can sit in a detection catalog the same way a real detection engineering team would maintain it.

Table of Contents

Overview

  • Detection ID / Name
  • Purpose
  • MITRE ATT&CK Mapping

Detection Build

  • Required Log Sources
  • Detection Logic
  • Findings & Design Notes
  • Trigger Conditions
  • Severity

Response & Validation

  • Response / Triage Steps
  • Testing Evidence
  • Associated Dashboards

Roadmap

  • Planned Detection Chain
  • Future Improvements

Metadata

  • Owner
  • Last Reviewed / Version
  • References

Detection ID / Name

Alert : Certighost ( CVE-2026-54121 )


Purpose

Detects abuse of the AD CS certificate enrollment chase mechanism described in CVE-2026-54121. The rule flags certificate lifecycle events on the CA where the requester supplied chase target (the cdc attribute) does not resolve to the legitimate Domain Controller, which is the exact mechanism Certighost uses to make the CA issue a certificate containing Domain Controller identity data to a low privileged requester resulting to full domain compromise and take over.

The detection is anchored on the cdc chase target rather than machine account creation because Microsoft's advisory for CVE-2026-54121 lists the account precondition as either a default ms-DS-MachineAccountQuota value or an account the attacker already controls. A rule keyed on account creation would miss the second path entirely, and would also depend on account creation and exploitation happening within the same time window. The cdc check covers both paths and has no such dependency.


MITRE ATT&CK Mapping

This rule covers the certificate request and issuance stage of the attack chain.

TacticTechnique (ID)Evidence
Privilege EscalationAbuse Elevation Control Mechanism (T1548)Low-priv domain user escalates to Domain Controller privileges via forged AD CS certificate
Credential AccessSteal or Forge Authentication Certificates (T1649)Core of Certighost - cdc/rmd attributes used to obtain certificate with DC identity material
Credential AccessOS Credential Dumping: DCSync (T1003.006)TGT for DC account used to perform MS-DRSR replication - extracts krbtgt and all account hashes
Credential AccessGolden Ticket (T1558.001)With krbtgt hash, attacker forges Kerberos TGTs indefinitely, surviving password resets
Defense EvasionUse Alternate Authentication Material: Pass-the-Ticket (T1550.003)Certificate-based TGT used to authenticate as DC, then DCSync performed with that TGT
PersistenceCreate Account: Local Account (T1136.001)Machine account created via ms-DS-MachineAccountQuota to authenticate rogue LDAP endpoint
Lateral MovementUse Alternate Authentication Material (T1550)DC certificate grants full network access equivalent to the Domain Controller account
DiscoveryDomain Account (T1087.002)Initial LDAP enumeration discovers CA, DC, domain SID, GUID, and MAQ value

Required Log Sources

  • Index: wineventlog-lab
  • Source Type: WinEventLog
  • Logs Source: WinEventLog:Security
  • Host: DC01
  • Windows Event Codes queried directly by this rule's search:
    • 4886 (Certificate request received)
    • 4887 (Certificate issued)
    • 4888 (Certificate request denied)

Log sources confirmed live in Splunk, host DC01, EventCodes 4886/4887 present, chase target 172[.]66[.]66[.]33 extracted for Request IDs 12, 13, 14


Detection Logic

index=wineventlog-lab sourcetype=WinEventLog source="WinEventLog:Security"
  (EventCode=4886 OR EventCode=4887 OR EventCode=4888) cdc
  
| fields _time EventCode Request_ID Requester Attributes Subject host Message
| rex field=Message "(?m)^cdc:(?<chase_cdc>\S+)"
| where isnotnull(chase_cdc) AND lower(chase_cdc)!="dc01.atlasvec.lab"
| stats min(_time) as _time
        values(Requester)  as requester
        values(Attributes) as template
        values(chase_cdc)  as chase_target
        values(Subject)    as cert_subject
        values(EventCode)  as codes
        values(host)       as ca_host
  by Request_ID
  
| eval status   = case(mvfind(codes,"4887")>=0,"ISSUED",
                       mvfind(codes,"4888")>=0,"DENIED",
                       true(),"PENDING")

| eval severity = "critical"
| sort - _time
| rename ca_host as "CA Host", Request_ID as "Request ID",
         requester as "User Requester", template as "Certificate Template",
         chase_target as "Chase Target (cdc)", cert_subject as "Issued Subject",
         status as "Outcome", severity as "Severity",
         _time as "Timestamp"
| table "Timestamp" "CA Host" "Request ID" "User Requester" "Certificate Template" "Chase Target (cdc)" "Issued Subject" "Outcome" "Severity"

Alert configuration: Enabled, Scheduled/Cron, Trigger Condition = Number of Results greater than 0


Findings & Design Notes

  • Events are grouped by Request ID so the full lifecycle of one malicious request (received, then issued or denied) shows as a single row.

  • The initial iteration of this detection included Event ID 4741 (computer account created) as a precondition, based on the public proof of concept demonstrating account creation as part of the attack chain. However, Microsoft's advisory for CVE-2026-54121 lists the machine account precondition as either a default ms-DS-MachineAccountQuota value or a machine account already controlled by the attacker.

    An attacker taking the second path uses a machine account they already control and generates no 4741 event. The rule was updated to anchor solely on the cdc chase target, covering both exploitation paths by design.

    This also removes any dependency on the account creation and the certificate abuse happening within the same time window. An attacker could create the machine account days before or after the exploitation attempt and the rule still fires.


Trigger Conditions

下载工具