Certipy is the primary Linux tool for AD CS enumeration and exploitation: it finds vulnerable certificate templates (ESC1–ESC16), requests and forges certificates, authenticates via PKINIT/Schannel, and manages shadow credentials and CA configuration.
See ADCS for the full ESC1–ESC16 attack chains.
Common Variables
All commands below assume these environment variables are set:
Global Auth Flags
Every subcommand accepts these; omitted from individual examples for brevity.
find — Enumerate and Discover Vulnerabilities
Enumerate all CA and template configurations and check for ESC conditions.
req — Request Certificates
auth — Authenticate with a Certificate
Authenticate using a PFX to obtain either an NT hash (PKINIT) or a TGT. Falls back to LDAP shell via Schannel when PKINIT is unavailable.
The LDAP shell (-ldap-shell) supports common operations: add_user_to_group, set_rbcd, get_laps_password, change_password, set_dontreqpreauth. Type help once connected.
ca — Manage the Certificate Authority
Requires ManageCA or ManageCertificates rights. Used primarily in ESC7 and ESC5.
template — View and Modify Templates
forge — Create Golden Certificates
Requires the CA private key (obtained via ESC12 backup or physical access to CA).
relay — NTLM Relay to AD CS
Relay incoming NTLM authentication to the certsrv HTTP endpoint. Run while coercing a target machine’s authentication.
shadow — Shadow Credentials (msDS-KeyCredentialLink)
Add a Key Credential Link to a target account and authenticate via PKINIT. Requires WriteProperty on msDS-KeyCredentialLink.
account — Manage AD Accounts
Create, read, update, and delete user/computer accounts. Used in ESC9/ESC10/ESC14 to modify UPN or altSecurityIdentities.
cert — Manipulate Certificates Locally
Inspect, convert, and extract PFX files without connecting to a CA.
parse — Offline Analysis
Analyse AD CS registry exports from BOF tools (Certipy BOF, Certify) without network access.