certify

Enumerate and abuse Active Directory Certificate Services misconfigurations for privilege escalation.

15|1|Updated Feb 12, 2026
One-click install
npx skills add https://github.com/AeonDave/malskill --skill certify
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: certify
Source: https://github.com/AeonDave/malskill/tree/main/offensive-tools/windows/certify
Command: npx skills add https://github.com/AeonDave/malskill --skill certify

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill automates the detection and exploitation of misconfigurations within Active Directory Certificate Services (AD CS), enabling privilege escalation and attack surface mapping.

Core Features & Use Cases

  • Enumeration: Identifies vulnerable certificate templates (ESC1-ESC8).
  • Abuse: Requests certificates for alternate users and exploits template misconfigurations.
  • Use Case: Before launching an attack, an administrator can use this tool to quickly identify all ways an attacker could abuse AD CS to gain higher privileges within the domain.

Quick Start

Use the certify skill to find all vulnerable certificate templates.

Frequently Asked Questions about certify

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I enumerate Active Directory Certificate Services for vulnerable certificate templates?

To enumerate Active Directory Certificate Services misconfigurations, this Skill identifies vulnerable certificate templates including ESC1 through ESC8. It automates the detection of template flaws to map privilege escalation pathways within AD CS.

What are ESC1 through ESC8 vulnerabilities in AD CS?

ESC1 through ESC8 are specific Active Directory Certificate Services template misconfigurations that enable privilege escalation. This Skill audits AD CS security posture by identifying these vulnerabilities and checking if certificates can be requested for alternate users.

How can I audit my domain for AD CS privilege escalation risks?

You can audit your domain for AD CS privilege escalation risks by using this Skill to find all vulnerable certificate templates. It maps exploitation pathways and identifies misconfigurations before attackers can abuse them to gain higher privileges.

Can I request certificates for alternate users to test Active Directory Certificate Services abuse?

Yes, you can request certificates for alternate users to test AD CS abuse. This Skill facilitates certificate requests for alternate users and exploits template misconfigurations to demonstrate privilege escalation within the domain.

Does this Skill work for auditing Windows security without external dependencies?

Yes, this Skill works for auditing Windows security and Active Directory Certificate Services without external dependencies. It operates independently to identify ESC1-ESC8 template vulnerabilities and map exploitation pathways.

What is the best way to map attack surfaces in AD CS environments?

The best way to map attack surfaces in AD CS environments is to enumerate all vulnerable certificate templates. This Skill identifies ESC1-ESC8 misconfigurations and facilitates abuse to demonstrate potential privilege escalation pathways.