Edges
Enroll
The target node may be a Certificate Template or an Enterprise Certification Authority.
Abuse Info
The Enroll permission grants enrollment rights on the certificate template.
The following additional requirements must be met for a principal to be able to enroll a certificate:
- The certificate template is published on an enterprise CA
- The principal has Enroll permission on the enterprise CA
- The principal meets the issuance requirements and the requirements for subject name and subject alternative name defined by the template
Certify can be used to enroll a certificate on Windows:
Certipy can be used to enroll a certificate on Linux:
Opsec Considerations
When an attacker abuses a privilege escalation or impersonation primitive that relies on this relationship, it will necessarily result in the issuance of a certificate. A copy of the issued certificate will be saved on the host that issued the certificate.
References
This edge is related to the following MITRE ATT&CK tactic and techniques: