certify
Warn
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documents the use of
Certify.exe, an offensive security tool designed to enumerate and exploit misconfigured Active Directory Certificate Services (ESC1-ESC8 templates). - [COMMAND_EXECUTION]: The skill provides command examples for performing privilege escalation by requesting certificates with alternate User Principal Names (UPNs) using the
/altnameparameter. - [COMMAND_EXECUTION]: The skill instructs the agent on how to use
Rubeus.exeto request Kerberos Ticket-Granting Tickets (TGTs) and perform Pass-the-Ticket (PTT) attacks using exported certificates.
Audit Metadata