Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Adds support for ESC14 #255

Open
wants to merge 3 commits into
base: main
Choose a base branch
from
Open

Conversation

RemiEC
Copy link

@RemiEC RemiEC commented Feb 13, 2025

Added the detection of users and computers configured with weak certificate mapping as part of ESC14 detection (cf. https://posts.specterops.io/adcs-esc14-abuse-technique-333a004dc2b9)

certipy find -u [email protected] -p Passw0rd -dc-ip 172.16.126.128 -esc14

The use of this flag only affects the console output and the .txt file as to not disrupt other tools (e.g. BloodHound ingestor).

As the requirements are very specific and weak certificate mappings are due to be rendered inusable by September 2025, the step of identifying usable certificate templates is still manual.

Identification of users with weak certificate mapping
Certipy_ESC14_1

Details found in the .txt file
Certipy_ESC14_2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant