logo

Abusing Active Directory Certificate Services (Part 4)

ID: dd8135be-70bd-5bea-bcd9-9a21342ce803

STIX ID: report--dd8135be-70bd-5bea-bcd9-9a21342ce803

Feed Name: Black Hills Infosec Blog

Threat Score
75/100

Date Published: 2024-05-30

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog post explains how misconfigurations in Active Directory Certificate Services (ADCS) — specifically overly permissive enrollment rights and insecure Extended Key Usage settings — enable ESC2 and ESC3 escalation techniques. Using Certipy, an attacker with a low-privilege account can request certificates (including Any Purpose or Certificate Request Agent templates), generate PFX files, request certificates on behalf of privileged accounts, extract Kerberos TGTs and NT hashes, and achieve persistent domain admin access. The article includes examples, commands, detection (event IDs) and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.