
Introduction to ADCS Exploitation w/ Alyssa Snow & Kaitlyn Wimberley
Source: YouTube · Black Hills Information Security · published Sep 5, 2025 · 1:09:28
This webcast provides an overview of Active Directory Certificate Services (ADCS) and its role in domain privilege escalation 0:14.
Key Takeaways:
• ADCS exploitation is a prevalent technique for domain privilege escalation during internal network penetration tests 0:16.
• The presenters are operators from the Antioch team, a continuous penetration testing group at BHS 0:43.
• The session serves as an introduction to understanding ADCS mechanics and exploitation vectors 0:00.
Understanding ADCS is critical for security professionals aiming to identify and mitigate common privilege escalation paths in enterprise environments.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Welcome to our introduction to Active Directory Certificate Services Exploitation webcast. Um, today we're going to have a brief overview of Active Directory Certificate Services. Um, ADCS exploitation is one of the most common privilege escalation domain privilege escalation techniques that we use on our internal uh, network penetration tests if we if we have credentials and our assumed compromise type test. So before we before we go into Active Directory Certificate Services stuff, uh introduce ourselves a little bit more thoroughly than Brian did. So Caitlyn and I are each operators on the Antioch on the Antioch team here at BHS. If you're not familiar with Antioch, Antioch is our continuous penetration testing team. Uh we each started in 2022 roughly uh roughly within the same month. O…