abusing-adcs

Installation
SKILL.md

Abusing AD CS

A certificate authority in an Active Directory domain is usually the shortest path from a standard user to domain administrator, because certificate templates are permission objects that almost nobody audits. A single template that lets the enrollee supply their own subject name is a full domain compromise, and it is the default on more networks than it should be.

Only against domains you are authorized to test.

When to Use

  • The domain has a CA (pKIEnrollmentService objects exist)
  • certipy find or BloodHound reports vulnerable templates
  • You have any domain credential and need a privilege escalation path
  • You need durable domain persistence that survives a password reset
  • Reviewing PKI configuration defensively

When NOT to Use

Installs
21
GitHub Stars
146
First Seen
Jul 30, 2026
abusing-adcs — trilwu/secskills