logo

Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools

ID: 225ce4b8-fb7b-5110-b3d0-efc50df4d46c

STIX ID: report--225ce4b8-fb7b-5110-b3d0-efc50df4d46c

Feed Name: Palo Alto Networks Unit 42

Threat Score
80/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Stav Setty, Tom Fakterman and Shachar Roitman

...
...

This Unit 42 report details how attackers exploit misconfigured Active Directory Certificate Services (AD CS) — through vulnerable certificate templates (ESC1 and related techniques), PKINIT/key-trust misuse, and shadow credentials — to escalate privileges, impersonate high-privilege accounts, and maintain stealthy persistence. The report catalogs commonly used open-source tools (Certify, Certipy, PKINIT tools, Whisker/pyWhisker), provides detection strategies (Windows Event IDs, LDAP query monitoring, and Cortex XDR/XSIAM alerts), and highlights real-world usage by ransomware and state-sponsored actors, urging stronger template hygiene and behavioral detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.