Skip to content

Active Directory Certificate Services (ADCS) Attacks

Welcome to the wonderful world of Active Directory Certificate Services (ADCS), where Microsoft decided that handing out cryptographically signed skeleton keys to anyone who asks nicely was a stellar security posture.

ADCS is Microsoft’s Public Key Infrastructure (PKI) implementation. It provides everything an organization needs to issue and manage digital certificates. These certificates are used for a myriad of purposes: encrypting file systems, signing code, and most importantly for us—authenticating to the domain.

Unfortunately, out of the box, or when managed by an overworked sysadmin on a Friday afternoon, ADCS introduces massive privilege escalation vectors. Researchers have categorized these misconfigurations into various ESC (Escalation) techniques.

Below is your master index for weaponizing ADCS misconfigurations. Grab some coffee, fire up Certipy, and let's forge some trust.


The ESC Arsenal

Advanced Operations

  • Golden Certificate: The ultimate persistence mechanism. Steal the CA's private key and mint your own valid certificates for anyone, anytime.