Private/Show-ESC5p5AttackDetails.ps1

function Show-ESC5p5AttackDetails {
    <#
        .SYNOPSIS
        Shows attack details for ESC5p5Combo vulnerabilities.
    #>

    [CmdletBinding()]
    param (
        [Parameter(Mandatory)]
        [array]$Results
    )

    Write-Host "=== ESC5p5: Full PKI Infrastructure Control ===" -ForegroundColor Red
    Write-Host ""
    Write-Host "Attack Description:" -ForegroundColor Yellow
    Write-Host "The principal has comprehensive control over PKI infrastructure including both" -ForegroundColor White
    Write-Host "certificate template containers AND enrollment services." -ForegroundColor White
    Write-Host ""
    
    # Display affected certificate template containers and enrollment services
    Write-Host "Affected Certificate Template Containers and Enrollment Services:" -ForegroundColor Yellow
    foreach ($result in $Results) {
        Write-Host " Principal: $($result.PrincipalName)" -ForegroundColor Cyan
        
        # Display certificate template containers
        if ($result.CertTemplatesContainers -and $result.CertTemplatesContainers.Count -gt 0) {
            Write-Host " Certificate Template Containers:" -ForegroundColor White
            foreach ($container in $result.CertTemplatesContainers) {
                Write-Host " - Container: $container" -ForegroundColor White
                
                # Find issues for this container to get specific rights
                $containerIssues = $result.ESC5CertTemplatesIssues | Where-Object { $_.Name -eq $container }
                
                if ($containerIssues) {
                    $uniqueRights = $containerIssues | ForEach-Object { $_.ActiveDirectoryRights } | Sort-Object -Unique
                    $uniqueSubtypes = $containerIssues | ForEach-Object { $_.Subtype } | Sort-Object -Unique
                    Write-Host " - Rights: $($uniqueRights -join ', ')" -ForegroundColor Gray
                    Write-Host " - Subtypes: $($uniqueSubtypes -join ', ')" -ForegroundColor Gray
                }
            }
        }
        
        # Display enrollment services
        if ($result.EnrollmentServices -and $result.EnrollmentServices.Count -gt 0) {
            Write-Host " Controlled Enrollment Services:" -ForegroundColor White
            foreach ($service in $result.EnrollmentServices) {
                Write-Host " - Service: $service" -ForegroundColor White
                
                # Find issues for this service to get specific rights
                $serviceIssues = $result.ESC5EnrollmentIssues | Where-Object { $_.Name -eq $service }
                
                if ($serviceIssues) {
                    $uniqueRights = $serviceIssues | ForEach-Object { $_.ActiveDirectoryRights } | Sort-Object -Unique
                    $uniqueSubtypes = $serviceIssues | ForEach-Object { $_.Subtype } | Sort-Object -Unique
                    Write-Host " - Rights: $($uniqueRights -join ', ')" -ForegroundColor Gray
                    Write-Host " - Subtypes: $($uniqueSubtypes -join ', ')" -ForegroundColor Gray
                }
            }
        }
        Write-Host ""
    }
    
    Write-Host "Attack Steps:" -ForegroundColor Yellow
    Write-Host "1. Create a new blank certificate template" -ForegroundColor Gray
    Write-Host "2. Modify the blank certificate template to match ESC1 requirements:`n - Subject Alternative Name (SAN) allowed`n - Client Authentication EKU`n - No Manager Approval`n - Enrollment Rights Assigned" -ForegroundColor Gray
    Write-Host "3. Enable the new certificate template" -ForegroundColor Gray
    Write-Host "4. Request a certificate with the SAN of a privileged account" -ForegroundColor Gray
    Write-Host "5. Use the certificate to authenticate as the privileged account" -ForegroundColor Gray
    Write-Host ""
    Write-Host "Risk Level: CRITICAL - Complete PKI infrastructure compromise" -ForegroundColor Red
}