AD CS (ESC1) to Domain Admin
A misconfigured Active Directory Certificate Services template lets a low-privileged user enrol a certificate as any account — a fast, quiet path to Domain Admin.
Scenario
An authorized internal engagement where you already hold a standard domain-user context. The domain runs Active Directory Certificate Services. The objective is to show whether a certificate-template misconfiguration (the ESC1 pattern) leads to domain compromise.
- 1
Discovery
Find a vulnerable certificate template
Enumerate the AD CS enrolment services and certificate templates and look for the ESC1 pattern: a template that lets low-privileged users enrol, permits client authentication, and allows the enrollee to supply an arbitrary subject (subjectAltName).
DetectionBulk LDAP reads of the PKI/configuration containers and template enumeration are visible; dedicated AD CS auditing flags unusual template queries.
MitigationInventory templates, remove 'enrollee supplies subject' on client-auth templates, and restrict enrolment rights.
- 2
Credential Access
Forge a certificate for a privileged account
Request a certificate from the vulnerable template while specifying a high-value account as the subject alternative name, yielding a client-authentication certificate that identifies you as that account.
DetectionCertificate issuance events (e.g., CA audit event 4886/4887) showing a SAN that does not match the requester are a high-fidelity signal.
MitigationEnable CA request/issuance auditing, require manager approval on sensitive templates, and set the SAN mapping policy strictly.
References adcs-attacks - 3
Credential Access
Exchange the certificate for Kerberos material
Use the forged certificate to authenticate via PKINIT and obtain a Kerberos TGT for the impersonated privileged account (recovering its NT hash where the flow allows).
DetectionPKINIT pre-authentication from an unusual host for a privileged account, and TGT requests backed by a certificate, are detectable with Kerberos logging.
MitigationEnforce strong certificate-to-account mapping (KB5014754), and monitor PKINIT for privileged accounts.
- 4
Domain Dominance
Act as the privileged account
Authenticate as the impersonated account and, with its rights, demonstrate domain-level control (for example directory replication), documenting everything for clean-up.
DetectionLogons for the privileged account from new hosts and non-DC replication (DCSync) are critical alerts.
MitigationTier admin accounts, restrict replication rights, and rotate krbtgt twice after suspected compromise.
Key takeaways
- A single over-permissive certificate template can equal Domain Admin — AD CS is in scope for every AD review.
- ESC1 is a configuration flaw, not an exploit: fix the template and enable CA auditing.
- Strong certificate-to-account mapping (KB5014754) closes the SAN-impersonation door.