{"id":1795,"date":"2026-07-25T07:19:49","date_gmt":"2026-07-25T00:19:49","guid":{"rendered":"https:\/\/vncybers.vn\/hieu-ve-certighost-nguoi-dung-ad-thuong-mao-danh-domain-controller\/"},"modified":"2026-07-25T07:19:49","modified_gmt":"2026-07-25T00:19:49","slug":"understanding-certighost-ad-users-impersonate-domain-controller","status":"publish","type":"post","link":"https:\/\/vncybers.vn\/en\/hieu-ve-certighost-nguoi-dung-ad-thuong-mao-danh-domain-controller\/","title":{"rendered":"Understanding Certighost: Why AD users can often impersonate a Domain Controller"},"content":{"rendered":"<p><strong>Certighost<\/strong> is the name of a newly disclosed exploitation chain published on 24\/07\/2026, in which a low-privileged Active Directory account can request a certificate for a Domain Controller and use that certificate to authenticate as the domain controller itself. The notable point is not password-based compromise, but abuse of internal certificate infrastructure, which many organizations still treat as a background component and rarely audit closely.<\/p>\n<p>The Hacker News reported that researchers H0j3n and Aniq Fakhrul released working exploit code for Certighost. When successful, an attacker can obtain a Domain Controller machine certificate, use Kerberos to authenticate with that server's privileges, and then perform DCSync to extract sensitive secrets such as the <strong>krbtgt<\/strong>. For many enterprises using Active Directory, this is the kind of risk that can turn an ordinary domain account into a stepping stone for full domain control.<\/p>\n<h2>What AD CS is and why it has become a hot spot<\/h2>\n<p>Active Directory Certificate Services, commonly abbreviated as <strong>AD CS<\/strong>, is the certificate issuance service in enterprise Windows environments. Certificates are used for many legitimate purposes, such as machine and user authentication, VPN, enterprise Wi-Fi, code signing, or internal TLS communication. Because certificates are directly tied to identity, certificates in AD CS carry weight similar to a login method.<\/p>\n<p>The problem appears when certificate templates, attribute write permissions, identity mapping, or issuance policies are configured too broadly. In recent years, penetration testing teams have repeatedly shown that AD CS can become a privilege escalation path when organizations focus only on passwords and overlook certificates. Certighost continues that trend: attackers do not need to break encryption; they look for a way to make the system issue them a certificate with a stronger identity.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/vncybers.vn\/wp-content\/uploads\/2026\/07\/certighost-inline.jpg\" alt=\"M\u00e1y ch\u1ee7 trung t\u00e2m d\u1eef li\u1ec7u minh h\u1ecda cho h\u1ea1 t\u1ea7ng Active Directory v\u00e0 AD CS\" \/><\/p>\n<h2>How the Certighost attack chain works<\/h2>\n<p>According to the initial description, Certighost starts from a low-privileged domain user. Instead of attacking the Domain Controller directly, the attacker targets the certificate issuance mechanism and tries to request a certificate representing the Domain Controller machine account. Once that certificate is accepted, Kerberos authentication may treat the attacker as the domain controller itself.<\/p>\n<p>The danger lies in the default privileges of the Domain Controller account. This account usually has the ability to replicate directory data to support synchronization between Domain Controllers. If impersonated, that replication right can be abused through the <strong>DCSync<\/strong>, allowing sensitive data to be requested from Active Directory without logging directly into the server.<\/p>\n<h2>Why DCSync is dangerous<\/h2>\n<p>DCSync is a technique that emulates Domain Controller replication behavior. In normal operations, Domain Controllers must share data so the domain remains stable. But if an untrusted identity gains replication rights, it can request account secrets, including password hashes and Kerberos-related keys.<\/p>\n<p>The <strong>krbtgt<\/strong> key is especially sensitive because it is used to sign Kerberos tickets in the domain. If this key is exposed, attackers can forge tickets, maintain long-term persistence, and bypass many traditional controls. Certighost is therefore not merely a certificate misconfiguration; it is a risk to the core trust layer of the entire Active Directory environment.<\/p>\n<h2>Signs organizations should review immediately<\/h2>\n<p>Environments with AD CS should review certificate templates that can be used for machine or user authentication, especially templates that allow requesters to supply their own identity information. Permissions such as write access to machine account attributes, overly broad enrollment rights, or loose certificate mapping configurations all need to be reassessed.<\/p>\n<p>Administrators should also review abnormal certificate issuance logs, certificate requests related to Domain Controllers, Kerberos activity that does not match the real machine, and DCSync events outside legitimate domain controllers. In large environments, watching only administrator logins is not enough; certificate infrastructure must be brought into regular monitoring scope.<\/p>\n<h2>Practical ways to reduce risk<\/h2>\n<p>The first measure is to inventory the entire AD CS environment: CA servers, certificate templates, groups allowed to enroll, auto-enrollment policies, and templates with client authentication or smart card logon purposes. Templates that are no longer used should be disabled, while active templates should restrict permissions to small groups with clear ownership.<\/p>\n<p>Next, organizations should apply least privilege to AD CS administration rights, enable complete logging for certificate issuance activity, and regularly use specialized audit tools to detect abuse-prone configurations. When domain keys are suspected to have been exposed through DCSync, the response process should include changing the <strong>krbtgt<\/strong> password in the correct sequence and reassessing the full authentication trail.<\/p>\n<h2>Lessons for defensive teams<\/h2>\n<p>Certighost restates an important reality: in Active Directory, identity is not only about passwords. Certificates, Kerberos keys, directory replication rights, and certificate template configurations are all part of the attack surface. A regular account can become a disaster when placed close to a misplaced trust configuration.<\/p>\n<p>For enterprises that depend on AD, the right approach is to treat AD CS as a critical asset on par with Domain Controllers. Periodic auditing, reduced enrollment rights, abnormal certificate monitoring, and DCSync scenario exercises help detect issues early before a small misconfiguration becomes a domain-wide incident.<\/p>\n<p style=\"text-align: right; margin-top: 40px;\"><em><strong>VNCyberS<\/strong> compiled from The Hacker News and Microsoft<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Certighost l\u00e0 t\u00ean g\u1ecdi c\u1ee7a m\u1ed9t chu\u1ed7i khai th\u00e1c m\u1edbi \u0111\u01b0\u1ee3c c\u00f4ng b\u1ed1 ng\u00e0y 24\/07\/2026, trong \u0111\u00f3 m\u1ed9t t\u00e0i kho\u1ea3n Active Directory c\u00f3 quy\u1ec1n th\u1ea5p c\u00f3 th\u1ec3 xin \u0111\u01b0\u1ee3c ch\u1ee9ng ch\u1ec9 cho Domain Controller v\u00e0 d\u00f9ng ch\u1ee9ng ch\u1ec9 \u0111\u00f3 \u0111\u1ec3 x\u00e1c th\u1ef1c nh\u01b0 ch\u00ednh m\u00e1y ch\u1ee7 \u0111i\u1ec1u khi\u1ec3n mi\u1ec1n. \u0110i\u1ec3m \u0111\u00e1ng ch\u00fa \u00fd kh\u00f4ng n\u1eb1m [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1793,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5],"tags":[459,461,460,466,458,463,462,467,464,465,263,153],"class_list":["post-1795","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-kien-thuc","tag-active-directory","tag-active-directory-certificate-services","tag-ad-cs","tag-certificate-security","tag-certighost","tag-dcsync","tag-domain-controller","tag-identity-security","tag-kerberos","tag-krbtgt","tag-microsoft","tag-the-hacker-news"],"_links":{"self":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/1795","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/comments?post=1795"}],"version-history":[{"count":0,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/1795\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media\/1793"}],"wp:attachment":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media?parent=1795"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/categories?post=1795"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/tags?post=1795"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}