T5AI for Cloud & Identity Attack Paths
AD CS attacks with Certipy
Active Directory Certificate Services is a privilege-escalation goldmine. Learn the ESC1 to ESC11 family of misconfigurations, why certificates are such durable credentials, and how Certipy enumerates and exploits them.
Advanced4 min readprofessional streamUpdated Sat Aug 01 2026 00:00:00 GMT+0000 (Coordinated Universal Time)
Learning objectives
- Explain why a certificate is a more durable credential than a password.
- Recognise the common ESC misconfigurations and what each one grants.
- Walk the Certipy find, request, auth workflow end to end.
- Use AI to interpret template flaws and plan exploitation while keeping every credential action behind human approval.
Academy subscription
Subscribe to unlock this module
This module is part of the StrikeOps Academy subscription. Unlock every paid module, with hands-on labs and knowledge checks.
- Every paid module across all tracks
- Hands-on labs and knowledge checks
- New content as it ships
$59/ month · or $590 / year
The Reference library and Foundation starters are free to read now.