logo

Certified Pre-Owned

ID: 1fd47643-7a3a-5b1c-a36b-24b8cfc13013

STIX ID: report--1fd47643-7a3a-5b1c-a36b-24b8cfc13013

Feed Name: SpecterOps Blog

Threat Score
85/100

Date Published: 2021-06-17

Date Updated: 2026-04-30

Author: Will Schroeder

...
...

This research brief (and linked whitepaper) analyzes widespread AD CS misconfigurations and weaknesses that enable attackers to obtain or forge certificates to authenticate as arbitrary domain users or machines, escalate privileges, and achieve long-term persistence (including “golden” forged certificates). It documents multiple escalation scenarios (ESC1–ESC8) — e.g., template misconfigurations, enrollment-agent abuse, EDITF/subjectAltName issues, NTLM relay against HTTP enrollment endpoints, and CA private key theft — provides offensive tooling and defensive auditing/remediation guidance, and warns that many enterprise environments are likely vulnerable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.