How You Can Impersonate Anyone in Active Directory (with Shikata!)

How You Can Impersonate Anyone in Active Directory (with Shikata!)

Source: YouTube · John Hammond · published Jun 25, 2025 · 26:29

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This video demonstrates how ESC1, a common Active Directory Certificate Services vulnerability, allows any authenticated user to escalate privileges by requesting certificates with impersonated Subject Alternative Names 0:38, potentially leading to full domain compromise.

Key Takeaways:
• ESC1 vulnerability occurs when certificate templates allow users to supply subject names in requests, enabling privilege escalation 0:47
• The web server template is vulnerable by default and commonly misconfigured in AD environments 4:28
• Attackers can combine ESC8 with ESC1 to gain initial access and escalate to domain admin 19:30
• The vulnerability allows any authenticated user to request a certificate impersonating another user, including domain admins 19:49
• ESC1 is still commonly found in enterprise environments due to historical misconfigurations 6:00

This vulnerability demonstrates how a simple misconfiguration in certificate templates can lead to complete domain compromise 23:10.

Sources:

  • 0:36 Introduction to ESC1 vulnerability
  • 1:48 Explanation of Subject Alternative Name (SAN) abuse
  • 20:22 Demonstration of requesting a certificate as a domain admin
  • 25:04 Discussion of global SAN settings (ESC6)

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All righty. Hey everyone, thanks so much for jumping in again. Hey, I'm excited to get together with Shakana. We were recording just the other day for some Active Directory certificate service abuse, exploitation, really cool tricks in an AD environment. Hey, I think we got to roll through what was it? Petite Potam the other day, ECS8, kind of starting from zero, starting with nothing, no access in the environment, but then speedrunning and jumping straight to domain access with full control. So, that was really awesome. But I know might not always be the lay of the land in today's day and age. So, hey, whatever you got up your sleeve this time around, Shakata, I'm super excited. What are we digging into? So, today we're going to be digging into what's known as ECS1 or escalation one as it…