Certificate of Compromise: Offensive Operations against Active Directory Certificate Service - Whitepaper
Authors/Creators
Description
Active Directory Certificate Services (ADCS) represents one of the most significant yet underappreciated attack surfaces in modern Windows domain environments. Deeply integrated into the Active Directory trust model, ADCS allows organizations to issue X.509 certificates trusted for domain authentication — but its default configurations and administrative flexibility have produced a large class of exploitable misconfigurations with direct paths to Domain Admin.
This paper provides a comprehensive technical reference for the complete ADCS attack taxonomy: ESC1 through ESC18 (certificate template and CA misconfigurations), THEFT1 through THEFT5 (certificate and private key theft), PERSIST1, PERSIST2 and PERSIST3 (user-level certificate persistence), and DPERSIST1 through DPERSIST3 (domain-level persistence via CA compromise). Each technique is documented with its root cause, prerequisites, step-by-step exploitation procedure using Certipy v5, detection opportunities, and remediation guidance, as well as relevant labs where possible.
A central focus is the September 2025 full enforcement baseline of KB5014754 — Microsoft's strong certificate-to-account binding patch — which definitively killed ESC9, ESC10, and ESC16 while leaving the majority of the attack surface intact, including relay-based techniques, enrollment agent abuse, CA permission misconfigurations, and all theft and persistence categories. Primary tooling throughout is Certipy v5, with impacket, bloodyAD, and supporting tools documented.
This paper has also been submitted to arXiv cs.CR (pending endorsement). Established cs.CR authors willing to endorse can use this link: https://arxiv.org/auth/endorse?x=E68XML
Files
certificate-of-compromise.pdf
Files
(4.2 MB)
| Name | Size | Download all |
|---|---|---|
|
md5:713b79ebb0c435561c09f6a821269a0f
|
4.2 MB | Preview Download |
Additional details
Software
- Repository URL
- https://github.com/thehackersbrain/certificate-of-compromise
- Development Status
- Active