AD CS
Enumerate AD CS
Certutil
Certutil -ping
Certutil.exe -tcainfoCrackMapExec
crackmapexec smb $ip -u $username -p $password -M adcsCertify
# Identify and list vulnerable templates with Certipy
certipy find -u $username -p $password -dc-ip $dcip -vulnerable
# Identify and list vulnerable templates with Certify
Certify.exe find /vulnerableExploitation
EDITF_ATTRIBUTESUBJECTALTNAME2 (ESC6)
Exploiting ESC1
Mitigation
References
Last updated
