Your certificate authority is the soft spot now.
Unit 42 dropped a deep look at Active Directory Certificate Services exploitation this week, and the findings should change how you score your internal attack surface. AD CS, the PKI infrastructure most Windows shops stood up years ago and rarely revisit, is being weaponized through template misconfigurations and shadow credential abuse to hand attackers domain admin without ever touching a domain controller exploit. Modern cybersecurity has shifted. The harder challenge now is noticing when attackers have quietly promoted themselves inside your perimeter using infrastructure you already trust.
AD CS Is a Cybersecurity Blind Spot
AD CS sits in a uniquely dangerous position. It issues certificates that domain controllers accept as authentication, which means a misconfigured template is a direct path to impersonating anyone in the directory, including Domain Admins. Most organizations stood up their internal CA to enable smart cards or 802.1X, treated it as solved infrastructure, and never came back.
Templates got copied. Permissions were never reviewed. Auto-enrollment crept onto user-writable objects.

The result is a quiet, persistent escalation channel. Tools like Certipy and the older Certify have automated discovery of vulnerable templates (ESC1 through ESC16 at this point), and Unit 42 is documenting active campaigns using shadow credential techniques where attackers write to msDS-KeyCredentialLink on a target account and then authenticate as that account with a freshly minted certificate. The traffic looks like clean authentication. Your firewall has no opinion about it. Your EDR sees signed Kerberos.
This is what makes the AD CS attack surface so corrosive to defense in depth. Every signal looks legitimate.
What to Actually Do This Week
If you haven’t audited your internal PKI in the last twelve months, treat this as overdue. The good news is that AD CS security hardening is concrete, well-documented, and almost entirely free.
- Run Certipy or PSPKIAudit against your environment in find mode. You will discover ESC1, ESC2, ESC4, or ESC8 conditions in most production directories. Treat the output as a punch list.
- Disable the Web Enrollment role and any HTTP-based certificate endpoints unless you have a documented reason. ESC8 (NTLM relay to web enrollment) remains one of the most common privilege escalation paths in the wild.
- Remove “Supply in request” from any certificate template that does not strictly need it. That single flag is the basis for ESC1.
- Review who has Write permissions on certificate templates and on the CA itself. The list should be tiny. It rarely is.
- Enforce certificate mapping strong enforcement (KB5014754) and audit any certificates with weak SAN-based mappings.
For threat detection, the highest-value signal is event 4886 and 4887 on the CA server combined with 4768 and 4769 Kerberos events. Certificate issuance for a Domain Admin from an unusual requester is a five-alarm fire, and almost no one alerts on it. Add the rule to your SIEM today. Pair it with monitoring on writes to msDS-KeyCredentialLink, which is the shadow credential primitive and has effectively no legitimate use outside Windows Hello for Business enrollment.
Your incident response runbook should include certificate revocation steps. If an attacker minted a certificate during dwell time, password resets do nothing. The cert remains valid until you revoke it or it expires, often a year or more later. Plenty of post-eviction reentries trace back exactly here.
The Wider Pattern
AD CS is one example of a broader truth defenders keep relearning the hard way. The infrastructure you trust the most is the infrastructure you audit the least. It’s the certificate authority you stood up in 2018. It’s the Jenkins plugin marketplace that pushed a trojaned Checkmarx package over the weekend, infostealer included. It’s the iOS update that silently shipped 84 CVE fixes Monday afternoon. Each of these systems is trusted by design, and that trust is exactly what attackers are buying.
Frame Security just emerged from stealth with $50 million to teach users to recognize phishing. That’s fine, useful even. No awareness program closes an ESC1 template. No amount of training prevents a service account from being shadow-credentialed by an attacker who already has WriteDACL on it. The hard work of cyber security is structural, and most of it is boring: permissions reviews, template audits, certificate revocation procedures, SIEM rules nobody volunteered to write.
The attackers documented by Unit 42 are using techniques SpecterOps wrote up in 2021. Nothing novel here. The techniques keep working because nobody hardened the thing.
So harden the thing. Pull a Certipy report this week. Schedule a quarterly PKI review the same way you schedule patch cycles. If your runbook can’t answer “how do we revoke a rogue certificate at 2am,” fix that before you find out under fire.
The right to issue certificates is the new crown jewel of your domain. Treat it accordingly.
Sources
- Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools
- Official CheckMarx Jenkins package compromised with infostealer
- Apple Patches Everything
- Frame Security Emerges From Stealth With $50M for Awareness and Training Platform
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
