← All walkthroughs

AD CS (ESC1) to Domain Admin

A misconfigured Active Directory Certificate Services template lets a low-privileged user enrol a certificate as any account — a fast, quiet path to Domain Admin.

On-prem Active Directory + AD CS Advanced Active DirectoryAD CSCertificates
Authorized testing only. This is a conceptual, defensive-aware walkthrough that maps an attack path to MITRE ATT&CK, detection and mitigation, and links to references for the detail. It is not a copy-paste playbook. Use it only against systems you own or are explicitly permitted to test.

Scenario

An authorized internal engagement where you already hold a standard domain-user context. The domain runs Active Directory Certificate Services. The objective is to show whether a certificate-template misconfiguration (the ESC1 pattern) leads to domain compromise.

  1. 1

    Discovery

    Find a vulnerable certificate template

    Enumerate the AD CS enrolment services and certificate templates and look for the ESC1 pattern: a template that lets low-privileged users enrol, permits client authentication, and allows the enrollee to supply an arbitrary subject (subjectAltName).

    Detection

    Bulk LDAP reads of the PKI/configuration containers and template enumeration are visible; dedicated AD CS auditing flags unusual template queries.

    Mitigation

    Inventory templates, remove 'enrollee supplies subject' on client-auth templates, and restrict enrolment rights.

  2. 2

    Credential Access

    Forge a certificate for a privileged account

    Request a certificate from the vulnerable template while specifying a high-value account as the subject alternative name, yielding a client-authentication certificate that identifies you as that account.

    Detection

    Certificate issuance events (e.g., CA audit event 4886/4887) showing a SAN that does not match the requester are a high-fidelity signal.

    Mitigation

    Enable CA request/issuance auditing, require manager approval on sensitive templates, and set the SAN mapping policy strictly.

    References adcs-attacks
  3. 3

    Credential Access

    Exchange the certificate for Kerberos material

    Use the forged certificate to authenticate via PKINIT and obtain a Kerberos TGT for the impersonated privileged account (recovering its NT hash where the flow allows).

    Detection

    PKINIT pre-authentication from an unusual host for a privileged account, and TGT requests backed by a certificate, are detectable with Kerberos logging.

    Mitigation

    Enforce strong certificate-to-account mapping (KB5014754), and monitor PKINIT for privileged accounts.

  4. 4

    Domain Dominance

    Act as the privileged account

    Authenticate as the impersonated account and, with its rights, demonstrate domain-level control (for example directory replication), documenting everything for clean-up.

    Detection

    Logons for the privileged account from new hosts and non-DC replication (DCSync) are critical alerts.

    Mitigation

    Tier admin accounts, restrict replication rights, and rotate krbtgt twice after suspected compromise.

    References mimikatz · impacket

Key takeaways

  • A single over-permissive certificate template can equal Domain Admin — AD CS is in scope for every AD review.
  • ESC1 is a configuration flaw, not an exploit: fix the template and enable CA auditing.
  • Strong certificate-to-account mapping (KB5014754) closes the SAN-impersonation door.