source
ESC1

ESC1 - Abuse Active Directory Certificate Services.

getnthash.py

Use Kerberos U2U to submit a TGS request for yourself.

ESC8

ESC8 - Abuse Active Directory Certificate Services.

gets4uticket.py

Gets an S4U2self ticket impersonating given user.

gettgtpkinit.py

Requests a TGT using Kerberos PKINIT and either a PEM or PFX based certificate+key.

Certi

Utility to play with ADCS, allows to request tickets and collect information about related objects.

Certify

Active Directory certificate abuse.

Certipy

Active Directory Certificate Services enumeration and abuse.

PKINITtools

Tools for Kerberos PKINIT and relaying to AD CS.

Search knowledge base