Certify is an open-source offensive security tool developed by SpecterOps for identifying and abusing insecure Active Directory Certificate Services configurations. It enumerates certificate templates and enrollment permissions to identify conditions that permit authentication-capable certificate enrollment or requester-controlled certificate subjects. In vulnerable Active Directory environments, these weaknesses can enable impersonation of privileged accounts and escalation to domain-level administrative access. It is used by penetration testers and has also been observed in ransomware intrusions, including activity attributed to Interlock.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Post-compromise activity includes active reconnaissance, data collection, lateral movement, and the use of legitimate tools such as ConnectWise ScreenConnect, Volatility, and Certify for credential theft and privilege escalation.
These issued certificates can then be used with Rubeus to authenticate to Active Directory as this user, for as long as the certificate is valid.
$EncodedAssemblyName = [System.Reflection.Assembly]::Load([Convert]::FromBase64String("EncodedValueGoesHere"))
If the certificate template lacks the required security extension (objectSid), and we control a user account, we can manipulate its attributes to request a certificate that gets mapped to a different identity, like a DA.
We start by finding certificate templates that are vulnerable to ESC9. For that, we can use Certipy and provide domain user credentials along with the domain controller IP.
That toolkit includes a PowerShell script designed to scoop up information about victims' Windows environments, such as... installed software... In addition to using custom malware, the ransomware slingers also deployed legitimate software... Volatility; and Certify...
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Certify is an open-source offensive security tool abused by Interlock to identify and exploit AD CS misconfigurations for certificate-based impersonation, privilege escalation, and persistence in support of ransomware operations.
A SpecterOps tool used to discover and exploit vulnerable Active Directory Certificate Services certificate templates, including requesting certificates that can be abused for impersonation and privilege escalation.
Named publicly available offensive tool used during the intrusion; the report also identifies a Certify YARA signature among detections.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.