It is an attack path
Certificate templates were configured for enrolment, not for adversaries. Most were last reviewed before the escalation research existed.
CoreEncryption audits, deploys and rescues enterprise PKI — with specialist depth in Microsoft ADCS, hardware security modules and certificate automation.
The situation
Most enterprise PKI is undocumented, unreviewed, and carrying a template misconfiguration that turns an ordinary user account into a domain administrator. Here is the shortest version of it.
Certificate templates were configured for enrolment, not for adversaries. Most were last reviewed before the escalation research existed.
One expired certificate, one unreachable CRL, one broken chain — and production stops at 03:00 on a Sunday, because the renewal was somebody’s calendar reminder.
Both problems are fixable.
Both are preventable.
Flagship engagement
We assess your CA hierarchy, certificate templates, permissions, revocation infrastructure and key protection against known attack paths and operational failure modes — then hand you a risk-ranked remediation roadmap your engineers can work straight from.
Who can exploit ESC1?
SAN = Administrator
ENROLLEE_SUPPLIES_SUBJECT lets the requester name any principal in the certificate.
Elapsed: minutes · The only trace left behind is an issued certificate
Findings shown are representative of a real ADCS assessment. Yours will be your own.
The deliverable
18 findings
Remediation roadmap
Ordered by risk removed per hour of engineering time, not by severity label. The first afternoon takes out more than the following three months.
Three pillars
How a health check runs
Thirty minutes. Hierarchy, scale, constraints, and whether an audit is even the right first move. If it is not, we will say so. No credentials change hands on this call.
Scripted and non-intrusive. Run by your team, or by us with your team watching. Nothing is written, nothing is restarted, nothing is enrolled — and the script is yours to read first.
Templates and permissions tested against the known escalation paths. Revocation, key protection, algorithm and validity hygiene tested against operational failure modes.
Every finding with impact, exploitability and a specific remediation — ordered so that the first week of work removes the most risk.
A working session with your engineers. You can fix it yourselves, or we can. Either way you keep the documentation and the verification scripts.
PS> Get-CAHierarchy -Summary
Forest : corp.example.com
Enterprise CAs : 3
ROOT-CA-01 Offline SHA256 RSA4096 exp 2039
ISSUING-CA-01 Online SHA256 RSA2048 exp 2031
ISSUING-CA-02 Online SHA1 RSA2048 exp 2029
Published templates : 41
Endpoints (est.) : 5,000 – 15,000
# scope agreed. no credentials exchanged.
PS> .\Collect-AdcsEvidence.ps1 -ReadOnly -Out .\evidence
[ok] enumerating CAs ................ 3
[ok] exporting template ACLs ........ 41
[ok] reading CA registry ............ 6
[ok] probing CDP / AIA endpoints .... 14
[ok] sampling issued certificates ... 500
[--] write operations attempted .... 0
[--] services restarted ............. 0
evidence written · SHA256 manifest signed
PS> certutil -v -dstemplate WorkstationAuth
msPKI-Certificate-Name-Flag = 1 (0x1)
CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT
pKIExtendedKeyUsage = "1.3.6.1.5.5.7.3.2"
Client Authentication
msPKI-Enrollment-Flag = 0 (0x0)
manager approval not required
>> supplied SAN + client auth + no approval
>> matches ESC1 — flag CRITICAL
PS> Get-Content .\report\index.md
# Findings — ordered by risk removed
1 CRITICAL ESC1 WorkstationAuth
2 CRITICAL ESC8 web enrolment over HTTP
3 HIGH ESC4 ACL: Authenticated Users
4 HIGH KEY-01 issuing CA key in software
5 HIGH REV-02 CDP unreachable externally
… 13 further findings
# each finding: impact · exploitability · fix
PS> .\Verify-Remediation.ps1 -Finding ESC1
before ENROLLEE_SUPPLIES_SUBJECT = 1
after ENROLLEE_SUPPLIES_SUBJECT = 0
after msPKI-Enrollment-Flag = PEND_ALL_REQUESTS
[ok] re-test: SAN injection refused
[ok] re-test: issued certificates unaffected
# your engineers ran this. we watched.
Representative output. Collection scripts are supplied for your review before anything runs.
Priority path
Describe the symptom, not just the system. The more specific you are, the faster we can tell you whether this is a template issue, a revocation issue, or something worse.
Revocation monitor — ISSUING-CA-01
Cache expired · EAP-TLS, VPN and code signing now refusing to validate
Source: CertificateServicesClient-AutoEnrollment
Event ID: 13
Level: Error
Certificate enrollment for Local system failed
to enroll for a Machine certificate with request
ID N/A from corp.example.com\ISSUING-CA-01
The RPC server is unavailable. 0x800706ba
>> 1,412 machines in 40 minutes
Why us
We do not resell CLM platforms or HSMs, and we do not carry a partner quota. Tooling gets recommended where it is justified and nowhere else. Every engagement leaves you with procedures your own engineers can run.
The capability list above describes working familiarity. No partnership or endorsement is implied.
Chain complete
Know what you have. Know where it’s vulnerable.
Know exactly what to fix next.