ad-adcs
Installation
SKILL.md
ADCS abuse (ESC1–ESC8)
When it applies
The domain runs Active Directory Certificate Services and you have any authenticated foothold. Misconfigured certificate templates or CA settings let a low-priv user obtain a certificate that authenticates as a privileged account — a fast, reliable path to Domain Admin.
Why it works
Certificates can be used for Kerberos (PKINIT) authentication. If a template lets an enrollee specify the subject (SAN) and permits client-auth, a normal user can request a cert as Domain Admin. Other ESCs abuse enrollment-agent rights, vulnerable CA ACLs, NTLM relay to the CA (ESC8), or the CA cert's private key.