abusing-adcs
Installation
SKILL.md
Abusing AD CS
A certificate authority in an Active Directory domain is usually the shortest path from a standard user to domain administrator, because certificate templates are permission objects that almost nobody audits. A single template that lets the enrollee supply their own subject name is a full domain compromise, and it is the default on more networks than it should be.
Only against domains you are authorized to test.
When to Use
- The domain has a CA (
pKIEnrollmentServiceobjects exist) certipy findor BloodHound reports vulnerable templates- You have any domain credential and need a privilege escalation path
- You need durable domain persistence that survives a password reset
- Reviewing PKI configuration defensively