Adcs Attacks

Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k). Use when the target runs a Certificate Authority and you want to find vulnerable certificate templates or CA misconfigurations, request a certificate that impersonates a privileged user, and know the exact certipy command, what each ESC actually checks, the Windows Event IDs that fire, and the remediation. ESC1 and ESC8 are the two you hit most in the field.

ADScanPro f37be6e 14.1 KB Updated

File contents

ADScanPro/Claude-AD/tree/main/skills/adcs-attacks commit f37be6e56c

Frequently asked questions

npx skillmds@latest add adscanpro/adcs-attacks