Pentesting Notebook
Ctrlk
  • Offensive security
    • Tooling
    • Virtualisation
    • Active Directory
      • Domain Recon
      • Object Permissions
      • Privileged Groups
      • Group Policy
      • Kerberos
      • AD CS
        • Finding AD CS
        • Misconfigured Certificate Templates
        • NTLM Relaying to ADCS endpoints
        • User & Computer Persistance
        • certipy-ad
        • Relay to HTTP AD CS (ESC8)
      • MS SQL Servers
      • SCCM
      • Credential Theft
      • LAPS
      • Forest & Domain Trusts
      • Domain Dominance
      • User Impersonation
      • Lateral Movement
      • Relaying
      • Pivoting
      • Zerologon
      • BloodyAD
      • Expired Passwords
    • Infrastructure
    • OSEP: Checklist
    • AV Evasion
    • UAC Bypass
    • Applocker
    • Initial compromise
    • Privilege Escalation
    • Persistence
    • Data Protection API
    • Windows Script Host
    • Cobalt Strike
    • MetaSploit
    • Linux
    • macOS
    • SQLMap
    • Regex / sed
    • Cracking
    • Misc.
    • Visual Studio notes
  • Generic
    • Commands
    • Web
    • Fixing Errors
Powered by GitBook
On this page
  1. Offensive security
  2. Active Directory
  3. AD CS

Relay to HTTP AD CS (ESC8)

Try this certipy relay thing:

https://www.vaadata.com/blog/ad-cs-security-understanding-and-exploiting-esc-techniques/#aioseo-exploitation-conditions-and-attack-sequence

Last updated 1 month ago