Since the release of Certified Pre-Owned in 2021, attacks targeting Active Directory Certificate Services (AD CS) have become increasingly common, with many privilege-escalation techniques emerging in recent years. This report breaks down ESC9–ESC15 techniques: how each path is exploited, how to detect it, and what practical defenses reduce risk. The focus is on hands-on detection: attacker artifacts, the most critical logs to collect and analyze, and monitoring tools to watch ADCS.
Event: Offzone
VIDEO RECORDING

Detection of ADCS ESC9-15 attacks
·1 min·

