White Papers

Investigating Active Directory Certificate Services Abuse: ESC1

active-directory-cover

The abuse of misconfigured Active Directory Certificate Services (AD CS) certificate templates has been a common method of privilege escalation for threat actors and red teams alike. Depending on the configuration of the certificate template, the impact of AD CS vulnerabilities can be devastating and lead to full domain compromise.

This white paper discusses the ESC1 certificate abuse technique, and the system artifacts and logs that can be used in both incident response and proactive engagements to help defenders develop detections and decrease the risk of AD CS abuse.

Author: Stephan Wolfert

Additional Resources
  • Modernize Legacy OT with Security logo

    Modernize Legacy OT with Security

    Read whitepaper
  • The Frontier AI Adversary:<br>How Frontier AI Is Changing the Nature of Cyberattacks logo

    The Frontier AI Adversary:<br>How Frontier AI Is Changing the Nature of Cyberattacks

    Read whitepaper
  • AI Detection and Response: A Runtime Security Architecture for AI Systems logo

    AI Detection and Response: A Runtime Security Architecture for AI Systems

    Read whitepaper