active-directory-certificate-services
AD Certificate Services attack playbook. Use when targeting misconfigured AD CS for privilege escalation via ESC1-ESC13 template abuse, NTLM relay to enrollment, CA officer abuse, and certificate-based persistence.
Security Assessment
About active-directory-certificate-services
AD CS Attack Playbook is a security-testing reference for assessing Active Directory Certificate Services, the PKI component of Active Directory, for misconfigurations that lead to privilege escalation and persistence. Aimed at penetration testers and red teams, it catalogs the ESC weakness classes from ESC1 through ESC13, along with NTLM relay to enrollment endpoints, certificate-authority officer abuse, and certificate-based persistence.
After an architecture overview of enterprise CAs, certificate templates, enrollment endpoints, and the certificate-to-Kerberos (PKINIT) authentication flow, it provides enumeration commands and then a section per technique. Coverage includes ESC1 (enrollee-supplied subject/SAN), ESC2 (Any Purpose EKU), ESC3 (enrollment agent), ESC4 (template ACL misconfiguration), ESC6 (the EDITF_ATTRIBUTESUBJECTALTNAME2 flag), ESC7 (ManageCA/ManageCertificates officer permissions), ESC8 (relay to the HTTP certsrv endpoint), ESC9 and ESC10 (weak certificate mapping), ESC11 (relay to RPC enrollment), and ESC13 (OID group link). Each technique states its precondition and gives concrete command examples using tools such as Certipy, Certify, certutil, ntlmrelayx, and PetitPotam. A certificate-based persistence section describes the golden certificate approach, where possession of the CA private key allows forging certificates for arbitrary users.
Use it when an engagement scope includes AD CS and you need to identify which ESC conditions are present and how they chain, for example using ACL abuse to reach ESC4, or coercion plus relay to reach ESC8. The skill notes that base models often miss enrollment prerequisite chains and the specific condition combinations that make a template exploitable, and it routes to companion playbooks for ACL abuse, Kerberos attacks, NTLM relay coercion, and lateral movement, plus an ESC matrix reference with per-variant conditions, one-liner commands, and detection indicators.
FAQ
What is this skill for?
It is a penetration-testing playbook for identifying and exploiting misconfigured Active Directory Certificate Services to escalate privileges and establish certificate-based persistence in a controlled security assessment.
Which ESC techniques are covered?
ESC1 through ESC13, including enrollee-supplied subject (ESC1), Any Purpose EKU (ESC2), enrollment agent (ESC3), template ACL abuse (ESC4), the EDITF_ATTRIBUTESUBJECTALTNAME2 flag (ESC6), CA officer permissions (ESC7), relay to HTTP or RPC enrollment (ESC8/ESC11), weak certificate mapping (ESC9/ESC10), and OID group link (ESC13).
What tools does it reference?
Certipy and Certify for enumeration and enrollment, certutil for CA configuration checks, and ntlmrelayx with coercion tools such as PetitPotam for relay-based techniques.
What is a golden certificate?
A certificate-based persistence technique: with the CA private key (backed up from the CA server), you can forge a certificate for any user in the domain.
How do you find vulnerable templates?
Enumerate with certipy find (optionally the -vulnerable flag) or Certify.exe find /vulnerable, or query templates manually over LDAP against the Certificate Templates container.
Install active-directory-certificate-services
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
yaklang/hack-skills