Overview of Certipy AD CS Toolkit
mainCertipy is an offensive and defensive toolkit designed for enumerating and abusing Active Directory Certificate Services (AD CS). It is used by red teamers, penetration testers, and defenders to identify and exploit AD CS misconfigurations, specifically covering the full range of ESC1 through ESC17 attack paths.
Key capabilities include:
- Discovering Certificate Authorities and Templates.
- Identifying misconfigurations.
- Requesting and forging certificates.
- Performing authentication using certificates.
- Relaying NTLM authentication to AD CS HTTP(S)/RPC endpoints.
- Supporting Shadow Credentials, Golden Certificates, and Certificate Mapping Attacks.