Skip to content

Commit f19504a

Browse files
authored
Merge pull request #258 from andrePKI/patch-1
Added description about ESC
2 parents 17fa663 + bdc64d8 commit f19504a

1 file changed

Lines changed: 5 additions & 0 deletions

File tree

Docs/Locksmith.md

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,11 @@ Locale: en-US
1010
## Description
1111
A small tool to find and fix common misconfigurations in Active Directory Certificate Services.
1212

13+
## Escalation paths
14+
ESC1, ESC2, etc., refer to a series of Active Directory Certificate Services (AD CS) escalation paths, originally documented by Will Schroeder and Lee Christensen in their landmark 2021 research on abusing AD CS titled "Certified Pre-Owned".
15+
16+
These ESC* vulnerabilities are not software vulnerabilities in the traditional sense (like CVEs), but rather misconfigurations or abuse paths that attackers can use to escalate privileges or persist in an environment using AD CS.
17+
1318
## Locksmith Cmdlets
1419
### [Invoke-Locksmith](Invoke-Locksmith.md)
1520
A small tool to find and fix common misconfigurations in Active Directory Certificate Services.

0 commit comments

Comments
 (0)