logo

Abusing Active Directory Certificate Services – Part One

ID: ead815ec-1a09-51e8-920b-a55ea54f5a8a

STIX ID: report--ead815ec-1a09-51e8-920b-a55ea54f5a8a

Feed Name: Black Hills Infosec Blog

Threat Score
75/100

Date Published: 2023-10-05

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog post demonstrates how misconfigured Active Directory Certificate Services (ADCS) certificate templates (notably the ESC1 condition) can allow low-privileged users to request certificates for arbitrary domain accounts, escalate to Domain Administrator, and maintain long-lived persistence due to multi-year certificate validity; it provides hands-on examples using Certipy to discover vulnerable templates, request certificates (including Kerberos and SID workarounds), extract credential hashes and Kerberos tickets, and recommends mitigations and monitoring (restrict template permissions, require manual approval, disable "Enrollee Supplies Subject", monitor event IDs 4886/4887/4768).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.