Private/Show-ESC4p5AttackDetails.ps1

function Show-ESC4p5AttackDetails {
    <#
        .SYNOPSIS
        Shows attack details for ESC4p5Combo vulnerabilities.
    #>

    [CmdletBinding()]
    param (
        [Parameter(Mandatory)]
        [array]$Results
    )

    Write-Host "=== ESC4p5: Combined Template Control Attack ===" -ForegroundColor Red
    Write-Host ""
    Write-Host "Attack Description:" -ForegroundColor Yellow
    Write-Host "The principal can control both disabled certificate templates AND enrollment services." -ForegroundColor White
    Write-Host "This combination allows enabling vulnerable templates and controlling their deployment." -ForegroundColor White
    Write-Host ""
    
    # Display affected templates, enrollment services, and rights
    Write-Host "Affected Templates and Enrollment Services:" -ForegroundColor Yellow
    foreach ($result in $Results) {
        Write-Host " Principal: $($result.PrincipalName)" -ForegroundColor Cyan
        
        # Display vulnerable templates
        if ($result.VulnerableTemplates -and $result.VulnerableTemplates.Count -gt 0) {
            Write-Host " Vulnerable Templates:" -ForegroundColor White
            foreach ($template in $result.VulnerableTemplates) {
                Write-Host " - Template: $template" -ForegroundColor White
                
                # Find issues for this template to get specific rights
                $templateIssues = $result.ESC4dIssues | Where-Object { 
                    $_.DirectoryEntry -and $_.DirectoryEntry.Properties['name'].Value -eq $template 
                }
                
                if ($templateIssues) {
                    $uniqueRights = $templateIssues | ForEach-Object { $_.ActiveDirectoryRights } | Sort-Object -Unique
                    $uniqueSubtypes = $templateIssues | ForEach-Object { $_.Subtype } | Sort-Object -Unique
                    Write-Host " - Rights: $($uniqueRights -join ', ')" -ForegroundColor Gray
                    Write-Host " - Subtypes: $($uniqueSubtypes -join ', ')" -ForegroundColor Gray
                }
            }
        }
        
        # Display enrollment services
        if ($result.EnrollmentServices -and $result.EnrollmentServices.Count -gt 0) {
            Write-Host " Controlled Enrollment Services:" -ForegroundColor White
            foreach ($service in $result.EnrollmentServices) {
                Write-Host " - Service: $service" -ForegroundColor White
                
                # Find issues for this service to get specific rights
                $serviceIssues = $result.ESC5EnrollmentIssues | Where-Object { $_.Name -eq $service }
                
                if ($serviceIssues) {
                    $uniqueRights = $serviceIssues | ForEach-Object { $_.ActiveDirectoryRights } | Sort-Object -Unique
                    $uniqueSubtypes = $serviceIssues | ForEach-Object { $_.Subtype } | Sort-Object -Unique
                    Write-Host " - Rights: $($uniqueRights -join ', ')" -ForegroundColor Gray
                    Write-Host " - Subtypes: $($uniqueSubtypes -join ', ')" -ForegroundColor Gray
                }
            }
        }
        Write-Host ""
    }
    
    Write-Host "Attack Steps:" -ForegroundColor Yellow
    Write-Host "1. Modify the identified certificate template to match ESC1 requirements:`n - Subject Alternative Name (SAN) allowed`n - Client Authentication EKU`n - No Manager Approval`n - Enrollment Rights Assigned" -ForegroundColor Gray
    Write-Host "2. Enable the certificate template" -ForegroundColor Gray
    Write-Host "3. Request a certificate with the SAN of a privileged account" -ForegroundColor Gray
    Write-Host "4. Use the certificate to authenticate as the privileged account" -ForegroundColor Gray
    Write-Host ""
    Write-Host "Risk Level: CRITICAL - Multi-stage attack with full template control" -ForegroundColor Red
}