ESCX
AD CS ESC Security Assessment
Domain-
ModeLive
Generated2026-08-29T21:55:36.6762443+03:00
94.4 / 100
A

AD CS Security Posture

Read-only, non-destructive ESC1–ESC16 assessment · 16 findings

Certificate Authorities

Enterprise CA objects (Enrollment Services) cross-checked against certutil -ping and the Cert Publishers group.

CAHostReachablecertutil pingCert Publishers
m3g-Root-CADC01.m3g.com.trTCP/135alivemember
testtestunreachableno responsemissing

Discrepancies (3)

  • Host unreachable test — CA host did not answer TCP/135 or ICMP.
  • CA service down test — CA 'test' does not respond to certutil -ping.
  • Missing from Cert Publishers test — Enrollment Service CA host is not a member of the Cert Publishers group.

CA Management Roles

Who can administer each CA (Manage CA) and approve/issue certificates (Issue and Manage Certificates). Assignments outside the default privileged groups — Administrators, Domain Admins, Enterprise Admins — are flagged for review (ESC7).

m3g-Root-CADC01.m3g.com.tr
2 non-default
M3G\attackManage CAnon-default
M3G\DnsAdminsIssue & Manage Certsnon-default
BUILTIN\AdministratorsManage CAIssue & Manage Certsdefault
M3G\Domain AdminsManage CAIssue & Manage Certsdefault
M3G\Enterprise AdminsManage CAIssue & Manage Certsdefault
testtest
Security descriptor unavailable — CA unreachable or ACL not collected.

Unused Published Templates

Templates published on a CA with no certificate that is still valid today - candidates to unpublish to reduce attack surface.

m3g-Root-CADC01.m3g.com.tr
Published 14With active cert 3Unused 13
AdministratorDirectoryEmailReplicationDomainControllerAuthenticationEFSEFSRecoveryKerberosAuthenticationMachineServerWebTempSubCAUserWeb4SrvWebForIISWebServer

Findings

ESC1 1

NotVulnerableESC1ESC1 - no enrollee-supplied-SAN authentication templates found0
Affected ObjectN/A
ExploitabilityTheoretical
Principals-
Evidence
TemplatesEvaluated37
RemediationNo action required for ESC1.
ReferenceSpecterOps "Certified Pre-Owned" (ESC1) / Certipy

ESC2 1

NotVulnerableESC2ESC2 - no Any-Purpose/No-EKU templates open to low-priv enrollment0
Affected ObjectN/A
ExploitabilityTheoretical
Principals-
Evidence
TemplatesEvaluated37
RemediationNo action required for ESC2.
ReferenceSpecterOps "Certified Pre-Owned" (ESC2) / Certipy

ESC3 1

NotVulnerableESC3ESC3 - no enrollment-agent templates open to low-priv enrollment0
Affected ObjectN/A
ExploitabilityTheoretical
Principals-
Evidence
TemplatesEvaluated37
CompanionTargetsPresent(empty)
RemediationNo action required for ESC3.
ReferenceSpecterOps "Certified Pre-Owned" (ESC3) / Certipy

ESC4 1

NotVulnerableESC4ESC4 - no templates with low-priv-writable DACLs0
Affected ObjectN/A
ExploitabilityTheoretical
Principals-
Evidence
TemplatesEvaluated37
RemediationNo action required for ESC4.
ReferenceSpecterOps "Certified Pre-Owned" (ESC4) / Certipy

ESC5 1

NotVulnerableESC5ESC5 - no PKI objects with low-priv-writable ACLs0
Affected ObjectN/A
ExploitabilityTheoretical
Principals-
Evidence
ObjectsEvaluated7
RemediationNo action required for ESC5.
ReferenceSpecterOps "Certified Pre-Owned" (ESC5) / Certipy

ESC6 1

ManualReviewESC6ESC6 - CA 'test' configuration unreachable3.2
Affected Objecttest
ExploitabilityTheoretical
Principals-
Evidence
ErrorCA unreachable; EditFlags could not be read. Verify EDITF_ATTRIBUTESUBJECTALTNAME2 manually.
DnsHostNametest
RemediationVerify certutil -config "<host>\<CA>" -getreg policy\EditFlags manually.
ReferenceSpecterOps "Certified Pre-Owned" (ESC6) / Certipy

ESC7 1

ManualReviewESC7ESC7 - CA 'test' security descriptor unavailable3.2
Affected Objecttest
ExploitabilityTheoretical
Principals-
Evidence
ErrorSecurityAces null or CA unreachable; ManageCA/ManageCertificates grants could not be evaluated.
ReachableFalse
DnsHostNametest
RemediationVerify CA security (certutil -config "<host>\<CA>" -getreg CA\Security) manually.
ReferenceSpecterOps "Certified Pre-Owned" (ESC7) / Certipy

ESC8 1

ManualReviewESC8ESC8 - endpoint 'https://DC01.m3g.com.tr/certsrv/' accepts NTLM; EPA state undetermined7.2
Affected Objecthttps://DC01.m3g.com.tr/certsrv/
ExploitabilityMedium
Principals-
Evidence
CaNamem3g-Root-CA
Urlhttps://DC01.m3g.com.tr/certsrv/
Schemehttps
NtlmSupportedTrue
EpaEnabled-
CesCepPresentTrue
NoteNTLM enabled but EPA state could not be determined over HTTPS; verify Extended Protection on the IIS site.
RemediationConfirm Extended Protection = Required on the IIS Windows Authentication settings for this endpoint.
ReferenceSpecterOps "Certified Pre-Owned" (ESC8) / Certipy / PetitPotam

ESC9 1

ESC10 1

ESC11 1

ESC12 1

ManualReviewESC12ESC12 - verify HSM/host key-protection posture on CA(s) (manual)1.8
Affected Objectm3g-Root-CA, test
ExploitabilityTheoretical
Principals-
Evidence
CertificateAuthoritiesm3g-Root-CA, test
LocalIndicatorsToCheckKSP provider name 'YubiHSM Key Storage Provider' (or other HSM KSP) on the CA signing key., Registry HKLM\SOFTWARE\Yubico\YubiHSM\ and yubihsm-connector.yaml for cleartext PIN., Default YubiHSM auth-key (ID 1 / password 'password')., Local Administrators / interactive shell access to the CA host (allows raw key or CertSvc abuse).
NoteRemote AD CS collection cannot read HSM PIN/auth-key or host access; confirmation is local-only. Never auto-flag Vulnerable.
RemediationChange default HSM auth-key/PIN, store secrets outside cleartext config, and restrict local admin/shell access on CA hosts.

ESC13 1

ManualReviewESC13ESC13 - OID-to-group link data not collected (manual)2.4
Affected ObjectmsPKI-Enterprise-Oid objects
ExploitabilityTheoretical
Principals-
Evidence
ReasonNo $Context.OidGroupLinks collection present; PkiAcls OidContainer entries carry ACLs only, not msDS-OIDToGroupLink values.
ManualCheckEnumerate CN=OID,CN=Public Key Services,CN=Services,CN=Configuration,<forest> for msPKI-Enterprise-Oid objects with msDS-OIDToGroupLink set., Resolve each linked group DN and assess whether it is privileged., Match the linked OID against each template IssuancePolicies (msPKI-Certificate-Policy)., A matching template with low-priv Enroll/AutoEnroll + client-auth EKU is ESC13 Vulnerable.
TemplatesWithIssuancePolicies(empty)
RemediationRemove msDS-OIDToGroupLink from OIDs mapped to privileged groups, or restrict enrollment on templates carrying those issuance policies.

ESC14 1

ManualReviewESC14ESC14 - altSecurityIdentities mappings not collected (manual)2.4
Affected ObjectPrivileged accounts
ExploitabilityTheoretical
Principals-
Evidence
ReasonNo $Context.AltSecurityIdentities collection present; account altSecurityIdentities values and DACLs are not gathered by current collectors.
ManualCheckEnumerate user/computer objects with altSecurityIdentities populated., Flag weak mapping types (see WeakMappingTypes)., Enumerate DACLs on privileged accounts for low-priv WriteProperty (altSecurityIdentities) / GenericWrite / GenericAll / WriteDacl., Weak value + a DC with StrongCertificateBindingEnforcement < 2 = exploitable (Variant B); writable ACL = exploitable regardless (Variant A).
WeakMappingTypesX509IssuerSubject (X509:<I>...<S>...) - WEAK, X509SubjectOnly (X509:<S>...) - WEAK, X509RFC822 (X509:<RFC822>email) - WEAK, Strong (safe): X509IssuerSerialNumber (<I><SR>), X509SKI (<SKI>), X509SHA1PublicKey (<SHA1-PUKEY>).
WeakBindingDCs(empty)
DcContextNo weak-binding DC observed (or DcMappings absent); Variant A (writable ACL) still applies.
RemediationReplace weak altSecurityIdentities mappings with strong types (SKI / SHA1PublicKey / IssuerSerialNumber), lock down write access to the attribute, and set StrongCertificateBindingEnforcement=2.

ESC15 1

ESC16 1

Exports & Backups

Read-only artifacts collected from each CA - what was captured and where it was written.

m3g-Root-CADC01.m3g.com.tr
c:\temp\internet\CA_Assesment_20260829_215651
Registry (CertSvc\Configuration)reg export
CertSvc_Configuration_20260829_215651.reg
The operation completed successfully.
Done
Registry dump (certutil -getreg)certutil
CA_Registry_getreg_20260829_215651.txt
Done
Issued certificatescertutil -view
Issued_Certificates_20260829_215651.csv
Done
CRL lists
CRLs\ (folder)
CertEnroll: 4 file(s). AD CDP: 2 CRL(s).
Done
CA backupACL: Admins only
CA_Backup\ (folder)
Full backup via Backup-CARoleService (database + private key). ACL hardened to Administrators/SYSTEM only.
Done