Active Directory
Certipy
Active Directory Certificate Services (AD CS) enumeration and abuse.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
AD CS is present — ESC1-ESC8 style attack paths.
How
find vulnerable templates; request certs; authenticate as target.
Why
AD CS has become a premier domain escalation avenue.
Commands & usage
certipy find -u user@domain.local -p pass -dc-ip 10.0.0.10
certipy req -u user@domain.local -p pass -ca CA-NAME -template VulnTemplate
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Tags
Related in Active Directory
Impacket
Python collection for Windows network protocols (SMB, WMI, Kerberos, etc.).
CrackMapExec / NetExec
Swiss army knife for pentesting Windows/Active Directory networks (NetExec successor).
BloodHound / SharpHound / AzureHound
Maps Active Directory attack paths using graph theory.
Rubeus
C# toolset for Kerberos abuse (AS-REP, kerberoast, tickets, etc.).
enum4linux-ng
SMB/Windows enumeration tool wrapping common Samba tools.
SMBMap
Enumerates Samba share drives across networks with permissions.