From cb273bb61b1acc5d48a0c188aff81f7c514f63b8 Mon Sep 17 00:00:00 2001 From: JonasBK Date: Wed, 3 Sep 2025 13:49:04 +0200 Subject: [PATCH 1/3] update registry collection methods --- docs/collect-data/permissions.mdx | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/docs/collect-data/permissions.mdx b/docs/collect-data/permissions.mdx index 362fc86f..33ef196f 100644 --- a/docs/collect-data/permissions.mdx +++ b/docs/collect-data/permissions.mdx @@ -105,7 +105,9 @@ Two additional types of data can enhance the findings - [DC Registry](/collect-d ## DC Registry -SharpHound collects the registry key values Kdc\\StrongCertificateBindingEnforcement and Schannel\\CertificateMappingMethods (described [here](https://support.microsoft.com/en-us/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16)) to determine the allowed certificate mapping methods by the DCs. The BloodHound ADCS edges ESC6, ESC9, and ESC10 require this data to be collected. +SharpHound collects the registry key values `Kdc\StrongCertificateBindingEnforcement` and `Schannel\CertificateMappingMethods` (described [here](https://support.microsoft.com/en-us/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16)) to determine the allowed certificate mapping methods by the DCs. The BloodHound ADCS edges ESC6, ESC9, and ESC10 require this data to be collected. + +SharpHound Enterprise additionally collects the `VulnerableChannelAllowList` value under `SYSTEM\CurrentControlSet\Services\Netlogon\Parameters` (described [here](https://support.microsoft.com/en-us/topic/how-to-manage-the-changes-in-netlogon-secure-channel-connections-associated-with-cve-2020-1472-f7e8cc17-0309-1d6a-304e-5ba73cd1a11e#theGroupPolicy)) to determine accounts allowed Netlogon secure channel without secure RPC. ### Collection and Permissions @@ -113,14 +115,12 @@ Collecting these registry key values requires membership of Administrators on th ## CA Registry -SharpHound collects the following registry key values on enterprise CAs stored under SYSTEM\\CurrentControlSet\\Services\\CertSvc\\Configuration\\<CA Name>: +SharpHound collects the following registry key values on enterprise CAs stored under `SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\`: -* **EnrollmentAgentRights - **Contains restrictions for enrollment agents. BloodHound will take the restrictions into account when calculating ADCS ESC3 edges, and assume no restrictions if not collected, as no restrictions are configured by default. -* **Security - **Contains the security descriptor for the enterprise CA i.e. the permissions for Enroll, ManageCA, and ManageCertificates edges against the enterprise CA. This security descriptor is also stored in the AD object of the enterprise CA. SharpHound collects both. The CA registry security descriptor holds the effective permissions. Changes in the CA registry security descriptor are replicated to the AD copy, however, not the other way. Therefore, collecting the CA registry security descriptor may reveal permissions of the enterprise CA that are not present if only collecting the AD object. -* **PolicyModules\\CertificateAuthority_MicrosoftDefault.Policy\\EditFlags - **SharpHound checks if the EDITF_ATTRIBUTESUBJECTALTNAME2 flag is present, required to calculate ADCS ESC6 edges. +* **EnrollmentAgentRights**: Contains restrictions for enrollment agents. BloodHound will take the restrictions into account when calculating ADCS ESC3 edges, and assume no restrictions if not collected, as no restrictions are configured by default. +* **Security**: Contains the security descriptor for the enterprise CA i.e. the permissions for Enroll, ManageCA, and ManageCertificates edges against the enterprise CA. This security descriptor is also stored in the AD object of the enterprise CA. SharpHound collects both. The CA registry security descriptor holds the effective permissions. Changes in the CA registry security descriptor are replicated to the AD copy, however, not the other way. Therefore, collecting the CA registry security descriptor may reveal permissions of the enterprise CA that are not present if only collecting the AD object. +* **PolicyModules\\<Active Policy>\\EditFlags**: SharpHound checks if the EDITF_ATTRIBUTESUBJECTALTNAME2 flag is present, required to calculate ADCS ESC6 edges. +* **RoleSeparationEnabled**: SharpHound checks whether the CA host enforces role separation i.e. users are not permitted to have the CA Administrator role and if they have the Certificate Manager role and vice versa. The registry key values are described in detail in the [Certified Pre-Owned whitepaper](https://specterops.io/wp-content/uploads/sites/3/2022/06/Certified_Pre-Owned.pdf). From 55d77d503e9ee5cf458c6d5384d07bf5ac796087 Mon Sep 17 00:00:00 2001 From: JonasBK Date: Tue, 9 Sep 2025 10:31:10 +0200 Subject: [PATCH 2/3] coderabbit suggestions --- docs/collect-data/permissions.mdx | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/docs/collect-data/permissions.mdx b/docs/collect-data/permissions.mdx index 33ef196f..b6a4c191 100644 --- a/docs/collect-data/permissions.mdx +++ b/docs/collect-data/permissions.mdx @@ -105,9 +105,9 @@ Two additional types of data can enhance the findings - [DC Registry](/collect-d ## DC Registry -SharpHound collects the registry key values `Kdc\StrongCertificateBindingEnforcement` and `Schannel\CertificateMappingMethods` (described [here](https://support.microsoft.com/en-us/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16)) to determine the allowed certificate mapping methods by the DCs. The BloodHound ADCS edges ESC6, ESC9, and ESC10 require this data to be collected. +SharpHound collects the registry values `Kdc\StrongCertificateBindingEnforcement` and `Schannel\CertificateMappingMethods` (described [here](https://support.microsoft.com/en-us/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16)) to determine the allowed certificate mapping methods on domain controllers (DCs). The BloodHound ADCS edges ESC6, ESC9, and ESC10 require this data to be collected. -SharpHound Enterprise additionally collects the `VulnerableChannelAllowList` value under `SYSTEM\CurrentControlSet\Services\Netlogon\Parameters` (described [here](https://support.microsoft.com/en-us/topic/how-to-manage-the-changes-in-netlogon-secure-channel-connections-associated-with-cve-2020-1472-f7e8cc17-0309-1d6a-304e-5ba73cd1a11e#theGroupPolicy)) to determine accounts allowed Netlogon secure channel without secure RPC. +SharpHound Enterprise additionally collects the `VulnerableChannelAllowList` value under `SYSTEM\CurrentControlSet\Services\Netlogon\Parameters` (described [here](https://support.microsoft.com/en-us/topic/how-to-manage-the-changes-in-netlogon-secure-channel-connections-associated-with-cve-2020-1472-f7e8cc17-0309-1d6a-304e-5ba73cd1a11e#theGroupPolicy)) to determine which accounts are allowed to use Netlogon secure channel connections without secure RPC. ### Collection and Permissions @@ -119,8 +119,8 @@ SharpHound collects the following registry key values on enterprise CAs stored u * **EnrollmentAgentRights**: Contains restrictions for enrollment agents. BloodHound will take the restrictions into account when calculating ADCS ESC3 edges, and assume no restrictions if not collected, as no restrictions are configured by default. * **Security**: Contains the security descriptor for the enterprise CA i.e. the permissions for Enroll, ManageCA, and ManageCertificates edges against the enterprise CA. This security descriptor is also stored in the AD object of the enterprise CA. SharpHound collects both. The CA registry security descriptor holds the effective permissions. Changes in the CA registry security descriptor are replicated to the AD copy, however, not the other way. Therefore, collecting the CA registry security descriptor may reveal permissions of the enterprise CA that are not present if only collecting the AD object. -* **PolicyModules\\<Active Policy>\\EditFlags**: SharpHound checks if the EDITF_ATTRIBUTESUBJECTALTNAME2 flag is present, required to calculate ADCS ESC6 edges. -* **RoleSeparationEnabled**: SharpHound checks whether the CA host enforces role separation i.e. users are not permitted to have the CA Administrator role and if they have the Certificate Manager role and vice versa. +* **PolicyModules\\<Active Policy>\\EditFlags**: SharpHound checks if the `EDITF_ATTRIBUTESUBJECTALTNAME2` flag is present, required to calculate ADCS ESC6 edges. +* **RoleSeparationEnabled**: SharpHound checks whether role separation is enforced (a user cannot be both CA Administrator and Certificate Manager). The registry key values are described in detail in the [Certified Pre-Owned whitepaper](https://specterops.io/wp-content/uploads/sites/3/2022/06/Certified_Pre-Owned.pdf). From d163f3b16370f0e93ef833c2a00ca865767cb1ee Mon Sep 17 00:00:00 2001 From: Jeff Matthews Date: Fri, 24 Oct 2025 08:43:37 -0500 Subject: [PATCH 3/3] chore: apply suggestions from code review --- docs/collect-data/permissions.mdx | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/collect-data/permissions.mdx b/docs/collect-data/permissions.mdx index b6a4c191..a353b4a5 100644 --- a/docs/collect-data/permissions.mdx +++ b/docs/collect-data/permissions.mdx @@ -118,8 +118,8 @@ Collecting these registry key values requires membership of Administrators on th SharpHound collects the following registry key values on enterprise CAs stored under `SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\`: * **EnrollmentAgentRights**: Contains restrictions for enrollment agents. BloodHound will take the restrictions into account when calculating ADCS ESC3 edges, and assume no restrictions if not collected, as no restrictions are configured by default. -* **Security**: Contains the security descriptor for the enterprise CA i.e. the permissions for Enroll, ManageCA, and ManageCertificates edges against the enterprise CA. This security descriptor is also stored in the AD object of the enterprise CA. SharpHound collects both. The CA registry security descriptor holds the effective permissions. Changes in the CA registry security descriptor are replicated to the AD copy, however, not the other way. Therefore, collecting the CA registry security descriptor may reveal permissions of the enterprise CA that are not present if only collecting the AD object. -* **PolicyModules\\<Active Policy>\\EditFlags**: SharpHound checks if the `EDITF_ATTRIBUTESUBJECTALTNAME2` flag is present, required to calculate ADCS ESC6 edges. +* **Security**: Contains the security descriptor for the enterprise CA (i.e., the permissions for Enroll, ManageCA, and ManageCertificates edges against the enterprise CA). This security descriptor is also stored in the AD object of the enterprise CA. SharpHound collects both. The CA registry security descriptor holds the effective permissions. Changes in the CA registry security descriptor are replicated to the AD copy, however, not the other way. Therefore, collecting the CA registry security descriptor may reveal permissions of the enterprise CA that are not present if only collecting the AD object. +* **PolicyModules\\<Active Policy>\\EditFlags**: SharpHound checks if the `EDITF_ATTRIBUTESUBJECTALTNAME2` flag is present, which is required to calculate ADCS ESC6 edges. * **RoleSeparationEnabled**: SharpHound checks whether role separation is enforced (a user cannot be both CA Administrator and Certificate Manager). The registry key values are described in detail in the [Certified Pre-Owned whitepaper](https://specterops.io/wp-content/uploads/sites/3/2022/06/Certified_Pre-Owned.pdf).