Skip to main content

ADCS

A collection of cheatsheets for abusing Active Directory Certificate Services, documenting ESC1 to ESC15 attack paths used for authentication bypass, impersonation, and privilege escalation.

Assess whether ADCS is installed

A cheatsheet about assessing whether Active Directory Certificate Services (ADCS) is installed us...

ESC1

A cheatsheet for ESC1 targeting certificate-based authentication vulnerabilities to exploit unaut...

ESC2

A cheatsheet for ESC2, a privilege escalation technique targeting certificate templates with Any ...

ESC3

A cheatsheet for ESC3 targeting certificate-based privilege escalation by abusing dual certificat...

ESC4

A cheatsheet about exploiting ESC4 misconfigurations in certificate templates using Certipy to ma...

ESC5

A cheatsheet for ESC5 targeting vulnerable PKI object access control to escalate privileges via c...

ESC6

A cheatsheet for ESC6 targeting privilege escalation by including user-defined values in the subj...

ESC7

A cheatsheet for ESC7 targeting vulnerable certificate authority access control by exploiting Man...

ESC8

A cheatsheet for ESC8 targeting authentication coercion by relaying NTLM hashes from a machine ac...

ESC9

A cheatsheet for exploiting ESC9 by targeting certificate misconfigurations and abusing GenericWr...

ESC10

A cheatsheet for ESC10 targeting privilege escalation by manipulating registry keys and certifica...

ESC11

A cheatsheet for exploiting the ESC11 vulnerability by targeting the IF_ENFORCEENCRYPTICERTREQUES...

ESC12

A cheatsheet for ESC12, targeting privilege escalation by exploiting vulnerabilities in system co...

ESC13

A cheatsheet for ESC13 targeting certificate enrollment vulnerabilities to exploit misconfigured ...

ESC14

A cheatsheet for ESC14 targeting certificate enrollment vulnerabilities to compromise target prin...

ESC15

A cheatsheet for ESC15 targeting certificate abuse via the Certificate Request Agent EKU, allowin...

Ressources

SpecterOps - Certified Pre-Owned SpecterOps - ADCS ESC13 Abuse Technique SpecterOps - ADCS ESC14 ...