An enterprise certificate authority is trusted by the whole domain. A certificate it issues is, in effect, a passport the domain will honour. That is why attackers love it: compromise the issuance rules and you do not need to steal a password, you mint an identity. Researchers at SpecterOps catalogued a family of these escalation paths, labelled ESC1 through the teens. ESC1 is the one you meet most often.
A certificate template is a form. It becomes dangerous when four conditions line up at once:
Put together, a normal user requests a certificate and simply types administrator as the subject. The CA issues it. The user then authenticates with that certificate through Kerberos PKINIT and is, to the entire domain, the administrator. Tools such as Certify and Certipy automate the whole path, which is why it does not take an expert.
msDS-KeyCredentialLink changes (event 5136) for the related shadow-credentials trick.ESC1 is not a software bug you patch; it is a configuration you have or you do not. That makes it a governance question, which is where a risk programme belongs. The certificate authority should be one of the highest-criticality assets in your inventory, with a named owner, a documented review of its templates, and that review dated and repeatable. An auditor who asks “when did you last review who can enrol from which template” is asking whether ESC1 is open. If the answer lives in one engineer’s memory, you cannot answer. If it lives in your register, you can.
Attack detail from Unit 42’s write-up on AD CS exploitation.
In a 45-minute session we run your own scope through SynapseRM: requirements, findings, scored risks, register entry. You keep the output either way.
A Belgium-based provider of cybersecurity solutions, and the team behind SynapseRM / TPRM.