💥Cyb3rBook

Home

❯

002 PENTESTING

❯

WINDOWS PENTESTING

❯

ADCS ESC8

ADCS - ESC8

Jun 13, 20261 min read

PRIMARY CATEGORY → ADCS

Theory

🛠️⌛


Enumeration

Certipy

Certipy

certipy find -dc-ip '<DC_IP>' -username '<USER>' -password '<PASSWD>' -stdout -vulnerable

Abuse - UNIX-Like

🛠️⌛


Abuse - Windows

🛠️⌛


Resources

Microsoft patching ESC8: Mitigating NTLM Relay on ADCS


Graph View

  • Theory
  • Enumeration
  • Abuse - UNIX-Like
  • Abuse - Windows
  • Resources

Backlinks

  • PASS THE CERTIFICATE (SCHANNEL)
  • 1433 - MSSQL
  • AD OFFENSIVE CHECKLIST
  • ADCS
  • KERBEROS RELAY OVER SMB
  • PASS THE CERTIFICATE

Created with Quartz v4.4.0 © 2026

  • GitHub
  • LinkedIn