See HERE.
Use Certipy for enumeration and identifying vulnerable templates.
certipy find -vulnerable -u <USER>@<DOMAIN> -p <PASSWORD> -dc-ip <DC
Account Persistance.
Domain Escalation
Domain Persistance
Certificate Theft
Last updated 2 months ago