ADCS
A collection of cheatsheets for abusing Active Directory Certificate Services, documenting ESC1 to ESC15 attack paths used for authentication bypass, impersonation, and privilege escalation.
Assess whether ADCS is installed
A cheatsheet about assessing whether Active Directory Certificate Services (ADCS) is installed us...
ESC1
A cheatsheet for ESC1 targeting certificate-based authentication vulnerabilities to exploit unaut...
ESC2
A cheatsheet for ESC2, a privilege escalation technique targeting certificate templates with Any ...
ESC3
A cheatsheet for ESC3 targeting certificate-based privilege escalation by abusing dual certificat...
ESC4
A cheatsheet about exploiting ESC4 misconfigurations in certificate templates using Certipy to ma...
ESC5
A cheatsheet for ESC5 targeting vulnerable PKI object access control to escalate privileges via c...
ESC6
A cheatsheet for ESC6 targeting privilege escalation by including user-defined values in the subj...
ESC7
A cheatsheet for ESC7 targeting vulnerable certificate authority access control by exploiting Man...
ESC8
A cheatsheet for ESC8 targeting authentication coercion by relaying NTLM hashes from a machine ac...
ESC9
A cheatsheet for exploiting ESC9 by targeting certificate misconfigurations and abusing GenericWr...
ESC10
A cheatsheet for ESC10 targeting privilege escalation by manipulating registry keys and certifica...
ESC11
A cheatsheet for exploiting the ESC11 vulnerability by targeting the IF_ENFORCEENCRYPTICERTREQUES...
ESC12
A cheatsheet for ESC12, targeting privilege escalation by exploiting vulnerabilities in system co...
ESC13
A cheatsheet for ESC13 targeting certificate enrollment vulnerabilities to exploit misconfigured ...
ESC14
A cheatsheet for ESC14 targeting certificate enrollment vulnerabilities to compromise target prin...
ESC15
A cheatsheet for ESC15 targeting certificate abuse via the Certificate Request Agent EKU, allowin...
Ressources
SpecterOps - Certified Pre-Owned SpecterOps - ADCS ESC13 Abuse Technique SpecterOps - ADCS ESC14 ...