Abusing Active Directory Certificate Services – Part 2
ID: 3626765c-9d08-597b-9755-7a641bc2ee13
STIX ID: report--3626765c-9d08-597b-9755-7a641bc2ee13
Feed Name: Black Hills Infosec Blog
Threat Score
This report demonstrates ESC4 — an ADCS certificate template permissions misconfiguration that permits non-admin Domain Users to modify templates and create certificates for other accounts (including Domain Administrators) using Certipy, providing a path to full domain compromise; it provides PoC commands, cleanup instructions, detection event IDs, hardening recommendations, and notes a Microsoft partial patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
