Skip to main content
Certipy is the primary Linux tool for AD CS enumeration and exploitation: it finds vulnerable certificate templates (ESC1–ESC16), requests and forges certificates, authenticates via PKINIT/Schannel, and manages shadow credentials and CA configuration.
See ADCS for the full ESC1–ESC16 attack chains.

Common Variables

All commands below assume these environment variables are set:

Global Auth Flags

Every subcommand accepts these; omitted from individual examples for brevity.

find — Enumerate and Discover Vulnerabilities

Enumerate all CA and template configurations and check for ESC conditions.

req — Request Certificates

auth — Authenticate with a Certificate

Authenticate using a PFX to obtain either an NT hash (PKINIT) or a TGT. Falls back to LDAP shell via Schannel when PKINIT is unavailable.
The LDAP shell (-ldap-shell) supports common operations: add_user_to_group, set_rbcd, get_laps_password, change_password, set_dontreqpreauth. Type help once connected.

ca — Manage the Certificate Authority

Requires ManageCA or ManageCertificates rights. Used primarily in ESC7 and ESC5.

template — View and Modify Templates

forge — Create Golden Certificates

Requires the CA private key (obtained via ESC12 backup or physical access to CA).

relay — NTLM Relay to AD CS

Relay incoming NTLM authentication to the certsrv HTTP endpoint. Run while coercing a target machine’s authentication.
Add a Key Credential Link to a target account and authenticate via PKINIT. Requires WriteProperty on msDS-KeyCredentialLink.

account — Manage AD Accounts

Create, read, update, and delete user/computer accounts. Used in ESC9/ESC10/ESC14 to modify UPN or altSecurityIdentities.

cert — Manipulate Certificates Locally

Inspect, convert, and extract PFX files without connecting to a CA.

parse — Offline Analysis

Analyse AD CS registry exports from BOF tools (Certipy BOF, Certify) without network access.