exploiting-adcs-with-certipy
Audited by Socket on Aug 4, 2026
2 alerts found:
Securityx2SUSPICIOUS. The skill is internally consistent and uses legitimate install sources, but its actual purpose is to equip an AI agent with offensive AD CS exploitation workflows that can produce Domain Admin compromise, credential recovery, and persistence. No clear malware or deceptive data-routing is present, but the exploit-focused capability and credential forwarding make it a high-risk security skill.
This fragment is documentation only and contains no executable logic to evaluate for supply-chain sabotage, hidden backdoors, or exfiltration. However, it clearly describes the tool’s intended offensive capabilities against AD CS (enumeration, certificate template abuse, NTLM relay to enrollment endpoints, shadow credentials, and certificate/key forging). Treat the broader dependency as high dual-use risk: allowlist and constrain usage, require authorization controls, and perform deeper code-level review of the actual implementation for any unexpected behavior beyond the documented functionality.