Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools
ID: 225ce4b8-fb7b-5110-b3d0-efc50df4d46c
STIX ID: report--225ce4b8-fb7b-5110-b3d0-efc50df4d46c
Feed Name: Palo Alto Networks Unit 42
Date Published: 2026-05-11
Date Updated: 2026-05-11
Author: Stav Setty, Tom Fakterman and Shachar Roitman
This Unit 42 report details how attackers exploit misconfigured Active Directory Certificate Services (AD CS) — through vulnerable certificate templates (ESC1 and related techniques), PKINIT/key-trust misuse, and shadow credentials — to escalate privileges, impersonate high-privilege accounts, and maintain stealthy persistence. The report catalogs commonly used open-source tools (Certify, Certipy, PKINIT tools, Whisker/pyWhisker), provides detection strategies (Windows Event IDs, LDAP query monitoring, and Cortex XDR/XSIAM alerts), and highlights real-world usage by ransomware and state-sponsored actors, urging stronger template hygiene and behavioral detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
