xsspresso
xsspresso
Tags/ Certificate Abuse

Certificate Abuse

2 writeups tagged with Certificate Abuse

ADMediumWindows

HTB — TombWatcher

Active Directory with ADCS misconfiguration. ESC1 certificate template abuse allows requesting a certificate as Domain Admin for full compromise.

#AD#ADCS#ESC1
Dec 1, 2025HackTheBox
ADMediumWindows

HTB — Signed

MSSQL with xp_cmdshell for initial RCE. Active Directory certificate abuse (ADCS) to impersonate Domain Admin.

#AD#MSSQL#ADCS
Nov 20, 2025HackTheBox