xsspresso
xsspresso
Tags/ ADCS

ADCS

7 writeups tagged with ADCS

ADMediumWindows

HTB — TombWatcher

Active Directory with ADCS misconfiguration. ESC1 certificate template abuse allows requesting a certificate as Domain Admin for full compromise.

#AD#ADCS#ESC1
Dec 1, 2025HackTheBox
ADMediumWindows

HTB — Signed

MSSQL with xp_cmdshell for initial RCE. Active Directory certificate abuse (ADCS) to impersonate Domain Admin.

#AD#MSSQL#ADCS
Nov 20, 2025HackTheBox
MiscEasyWindows

HTB — Fluffy

CVE-2025-24071 abuses .searchConnector-ms files to capture NTLMv2 hashes. Relay attack and ADCS ESC4 escalate to Domain Admin.

#NTLM Relay#ADCS#CVE-2025-24071
May 28, 2025HackTheBox
ADMediumWindows

HTB — StreamIO

SQLi on login page, LFI reveals PHP source. MSSQL xp_cmdshell for shell. Firefox DPAPI credential decryption leads to Domain Admin via ADCS.

#AD#SQLi#LFI
Jan 31, 2025HackTheBox
ADMediumWindows

HTB — EscapeTwo

MSSQL with xp_cmdshell after credential spraying. ADCS ESC4 template modification for certificate impersonation to gain Domain Admin.

#AD#MSSQL#ADCS
Jan 13, 2025HackTheBox
ADMediumWindows

HTB — Certified

Shadow Credentials attack via WriteProperty on user object. ADCS ESC9 certificate template abuse to impersonate a privileged account.

#AD#ADCS#Shadow Credentials
Jan 9, 2025HackTheBox
ADMediumWindows

HTB — Escape

MSSQL Silver Ticket attack via SPN enumeration. Responder captures NTLMv2 hash from SQL query, certificate auth for Domain Admin.

#AD#MSSQL#Silver Ticket
Nov 19, 2024HackTheBox