ADCS Security Resources
Welcome to the ultimate resource collection for Active Directory Certificate Services (AD CS) security. This page is designed to be a comprehensive reference for security experts, pentesters, and red teamers looking to deepen their understanding of AD CS vulnerabilities and exploitation techniques.
Tools
A C# tool to enumerate and abuse misconfigurations in AD CS
Learn MorePython tool for exploiting AD CS
Learn MoreA tool to escalate privileges in an AD environment by abusing AD CS
Learn MoreResearch Papers
Abusing Active Directory Certificate Services
Learn MorePractical guide to NTLM relaying to AD CS HTTP Endpoints
Learn MoreTechniques
Exploiting overly permissive certificate templates
Learn MoreAbusing Enrollment Agent templates
Learn MoreExploiting NTLM relay in AD CS
Learn MoreExternal Resources
MITRE ATT&CK framework entries related to AD CS
Learn MoreOfficial Microsoft documentation on securing AD CS
Learn MoreContribute to Our Knowledge Base
Our goal is to maintain the most comprehensive and up-to-date resource on ADCS Security. If you have additional resources, tools, or techniques that you believe would benefit the community, we encourage you to contribute.
Submit a Resource