Abusing Adcs

Enumerate and abuse Active Directory Certificate Services with Certipy and Certify — the ESC1 through ESC16 escalation paths, vulnerable template and CA configurations, NTLM relay to web enrollment, certificate-based authentication and persistence, and the strong-mapping changes that gate several of them. Use when a domain has a certificate authority, when Certipy or BloodHound reports vulnerable templates, or when escalating from a low-privilege domain user.

trilwu 9e59cc0 9.6 KB Updated

File contents

trilwu/secskills/tree/main/secskills-offense/skills/abusing-adcs commit 9e59cc045c

Frequently asked questions

npx skillmds add trilwu/abusing-adcs