Ad Certipy Esc Chain

ADCS abuse via Certipy — find vulnerable templates (ESC1-ESC15), request a certificate, authenticate as the target, dump the krbtgt. Full chain in 4 commands. Covers ESC1 (any SAN), ESC2 (any-purpose EKU), ESC3 (enrollment-agent), ESC4 (vulnerable ACL), ESC8 (NTLM relay to CA), ESC9/10/11/13.

purpleailab Updated

File contents

purpleailab/decepticon/tree/main/packages/decepticon/decepticon/skills/standard/ad/certipy-esc-chain commit 9c19c4f0ca

Frequently asked questions

npx skillmds@latest add purpleailab/ad-certipy-esc-chain