Active Directory Certificate Services (ADCS)
Overview
Enumeration
# Using PowerView
Get-ADObject -LDAPFilter "(objectClass=pKIEnrollmentService)" -Properties *
Get-ADObject -LDAPFilter "(objectClass=pKICertificateTemplate)" -Properties *
# Using Certify
Certify.exe find
Certify.exe find /vulnerable# Using PowerView
Get-ADObject -LDAPFilter "(objectClass=pKICertificateTemplate)" -Properties * | Select-Object Name, pkiPathLength, pkiPrivateKeyFlag, pkiEnrollmentFlag, pkiSubjectNameFlag
# Using Certify
Certify.exe find /template:*Authentication Testing
Configuration Testing
Exploitation
Post-Exploitation
BloodHound AD Integration
Tools
Best Practices
Resources
Last updated