ADCS Attacks

Active Directory Certificate Services is installed in over 90% of enterprise environments and is misconfigured in most of them. ESC1 through ESC15 cover the full spectrum: misconfigurations that let any authenticated user request a certificate as a Domain Admin, relay attacks against the enrollment endpoint, and techniques that create persistent backdoors using certificates that survive password resets.

Related Articles