> For the complete documentation index, see [llms.txt](https://watchdogsacademy.gitbook.io/attacking-active-directory/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://watchdogsacademy.gitbook.io/attacking-active-directory/active-directory-certificate-services-adcs/bloodhound/adcs-reconnaissance-and-enumeration-with-certipy-and-bloodhound.md).

# ADCS reconnaissance and enumeration (with certipy and bloodhound)

Active Directory Certificate Services (AD CS) in Windows Server® 2012. AD CS is the Server Role that allows you to build a public key infrastructure (PKI) and provide public key cryptography, digital certificates, and digital signature capabilities for your organization.

### Install Certipy

```
sudo pip3 install certipy-ad
```

* Let’s start the enumeration with certipy

```
sudo certipy find -u  joaquin.Pereida@maryland.local -p 'horse' -dc-ip 192.168.56.12 -bloodhound
```

<figure><img src="https://755243087-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FB2Dm6vWGbM7kQRITOyVl%2Fuploads%2FnB3Y3yjfeyZYQ9sNpeOl%2Fimage.png?alt=media&amp;token=0eb7e4ab-babe-48f3-8315-8cd3413ef6fe" alt=""><figcaption></figcaption></figure>

* This will search the certificate server, and dump all the information needed in three format :
  * bloodhound : a zip ready to import in bloodhound (if you use certipy 4.0 you will have to install the [bloodhound gui modified by oliver lyak](https://github.com/ly4k/BloodHound/releases), if you do not want to use the modified version, you must use the `-old-bloodhound` option)
  * json : information json formated
  * txt : a textual format
* Certipy 4.0 reintroduce also the `-vulnerable` option to show the vulnerable templates.

```
sudo certipy find -u joaquin.Pereida@maryland.local -p 'horse' -vulnerable -dc-ip 192.168.56.12 -stdout
```

* We can find an ESC1 vulnerable template :
  * Enrollment rights to all domain users
  * Client authentication
  * And Enroll supplies subject
  * There is also an ESC2 vulnerable template:

<figure><img src="https://755243087-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FB2Dm6vWGbM7kQRITOyVl%2Fuploads%2FyC6tQcYHiik0otBWfXhR%2Fimage.png?alt=media&amp;token=65990c80-1591-4ec4-9423-594f804fe36a" alt=""><figcaption></figcaption></figure>

And others vulnerable templates, let’s take a look in bloodhound.

* Import the zip file created with certipy.
* And take an overview with : PKI->Find certificate authority, select the certificate authority and click : “see enabled templates”

<figure><img src="https://755243087-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FB2Dm6vWGbM7kQRITOyVl%2Fuploads%2F4Mcvp9UywwGq2APW2QzR%2Fimage.png?alt=media&amp;token=f136014d-a176-455b-b055-0c6524da5e95" alt=""><figcaption></figcaption></figure>

>
