<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <title>Active Directory - Tag - Symsec</title>
    <link>https://symsec.net/tags/active-directory/</link>
    <description>Active Directory - Tag | Symsec</description>
    <generator>Hugo -- gohugo.io</generator><language>en</language><managingEditor>symeonpdm@gmail.com (Symeon Papadimitriou)</managingEditor>
      <webMaster>symeonpdm@gmail.com (Symeon Papadimitriou)</webMaster><lastBuildDate>Tue, 14 Jan 2025 01:03:19 &#43;0300</lastBuildDate><atom:link href="https://symsec.net/tags/active-directory/" rel="self" type="application/rss+xml" /><item>
  <title>Abusing ADCS for Domain Admin Privileges</title>
  <link>https://symsec.net/posts/stories/8sen0d1f/</link>
  <pubDate>Tue, 14 Jan 2025 01:03:19 &#43;0300</pubDate>
  <author>Symeon Papadimitriou</author>
  <guid>https://symsec.net/posts/stories/8sen0d1f/</guid>
  <description><![CDATA[Disclaimer: Please be aware that the scenario depicted is a replication in a locally configured domain environment. While the technical steps and attack path accurately represent the real client engagement, all workstations, user accounts, passwords, and naming conventions (such as certificate templates) have been altered to protect client confidentiality and comply with my NDA contract.
Introduction During an internal network assessment of a client’s Active Directory environment, I identified a critical misconfiguration that could allow unauthorized users to escalate their privileges to Domain Admin.]]></description>
</item>
</channel>
</rss>
