Certipy and ADCS

ACTIVE DIRECTORYADCSCERTIFICATESATTACK PATHS

NOTES

Certipy turns ADCS configuration into testable relationships: certificate authorities, templates, enrollment rights, issuance requirements, authentication EKUs, web enrollment, and account mapping.

The important question is not whether a template receives an ESC label. It is whether the controlled principal can satisfy every prerequisite and obtain authentication material for a more privileged identity.

VALIDATION

COMMANDS

certipy find -u USER@DOMAIN -p PASSWORD -dc-ip DC_IP -enabled -vulnerable
certipy req -u USER@DOMAIN -p PASSWORD -ca CA_NAME -template TEMPLATE
certipy auth -pfx identity.pfx -dc-ip DC_IP

GOTCHAS

DOCS

Certipy and ADCS documentation ↗

← Back to Resources