Compass Security Blog

Offensive Defense

Stealthy AD CS Reconnaissance

Introducing a certipy parse command to perform stealthy offline AD CS enumeration based on local registry data.

Continue reading

Relaying to AD Certificate Services over RPC

In June last year, the good folks at SpecterOps dropped awesome research on Active Directory Certificate Services (AD CS) misconfigurations. Since then, we find and report these critical vulnerabilities at our customers regularly. One of these new attack path is relaying NTLM authentication to unprotected HTTP endpoints. This allows an attacker to get a valid […]

Continue reading