AD Certificates

See HERE.

Use Certipy for enumeration and identifying vulnerable templates.

certipy find -vulnerable -u <USER>@<DOMAIN> -p <PASSWORD> -dc-ip <DC

Account Persistance.

Domain Escalation

Domain Persistance

Certificate Theft

Last updated