Exploit Active Directory Certificate Services (AD CS) misconfigurations, specifically ESC1. By requesting a certificate based on a overly permissive template that allows the enrollee to supply a Subject Alternative Name (SAN), an attacker can impersonate highly privileged users (like Domain Admins) and seamlessly escalate privileges across the entire AD environment.
Installation
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
Exploit Active Directory Certificate Services (AD CS) misconfigurations, specifically ESC1. By requesting a certificate based on a overly permissive template that allows the enrollee to supply a Subject Alternative Name (SAN), an attacker can impersonate highly privileged users (like Domain Admins) and seamlessly escalate privileges across the entire AD environment.
When operating in a Windows Active Directory environment and you discover that Active Directory Certificate Services (AD CS) is deployed (PKI infrastructure).
To massively escalate privileges from a standard domain user to Domain Admin by exploiting misconfigured certificate templates.
Prerequisites
Authorized scope and rules of engagement for the target environment
Appropriate tools installed on the attack/analysis platform
Understanding of the target technology stack and architecture
Documentation template ready for findings and evidence capture
Workflow
Phase 1: Identifying AD CS and Vulnerable Templates (ESC1)