ad-adcs

Installation
SKILL.md

ADCS abuse (ESC1–ESC8)

When it applies

The domain runs Active Directory Certificate Services and you have any authenticated foothold. Misconfigured certificate templates or CA settings let a low-priv user obtain a certificate that authenticates as a privileged account — a fast, reliable path to Domain Admin.

Why it works

Certificates can be used for Kerberos (PKINIT) authentication. If a template lets an enrollee specify the subject (SAN) and permits client-auth, a normal user can request a cert as Domain Admin. Other ESCs abuse enrollment-agent rights, vulnerable CA ACLs, NTLM relay to the CA (ESC8), or the CA cert's private key.

Installs
2
GitHub Stars
19
First Seen
7 days ago
ad-adcs — noorqureshi/sploitagent