<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>ADCS on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/adcs/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Sat, 12 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/adcs/index.xml" rel="self" type="application/rss+xml"/><item><title>HTB: TrustFall</title><link>https://wearethebug.dev/posts/htb-trustfall/</link><pubDate>Sat, 12 Sep 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-trustfall/</guid><description>TrustFall is an Insane-rated hybrid machine featuring a complex, multi-stage kill chain that bridges external web exploitation with deep Active Directory and ADCS abuse. Initial access requires chaining an osTicket arbitrary file read with a legacy telnetd vulnerability to compromise a Linux pivot host. Lateral movement involves intricate ACL/OU inheritance abuse, AS-REP roasting, and a sophisticated WSUS Man-in-the-Middle attack powered by a rogue certificate (ESC17) for local privilege escalation. The endgame tests cryptographic weaknesses and PKI administration, requiring the prediction of a time-seeded VBScript PRNG to compromise a PKI Manager, ultimately leading to full Certificate Authority takeover (ESC7) and Domain Admin compromise via DCSync.</description></item><item><title>VULNLAB: Mythical</title><link>https://wearethebug.dev/posts/vl-mythical/</link><pubDate>Wed, 06 Nov 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-mythical/</guid><description>Mythical is a Medium-rated small active directory chain on Vulnlab in which we start with an already running Mythic C2 beacon on an internal system. It is designed to practice operating through a C2 framework in a modern, challenging windows environment.</description></item><item><title>VULNLAB: Cicada</title><link>https://wearethebug.dev/posts/vl-cicada/</link><pubDate>Thu, 26 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-cicada/</guid><description>Cicada is a Medium-rated Windows Active Directory machine hosted on the VulnLab platform, that involves discovering a password inside an image on a public share. With that password an attacker is able to discover that the machine is vulnerable to ESC8 and can use Kerberos relaying to bypass self-relay restrictions in order to get a certificate as the machine account itself. With this new certificate, we are able to dump the hashes of the Administrator user and thus compromise the whole domain.</description></item><item><title>VULNLAB: Ifrit</title><link>https://wearethebug.dev/posts/vl-ifrit/</link><pubDate>Sun, 15 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-ifrit/</guid><description>Ifrit is an Assumed-Breach scenario with the main objective is getting domain administrator privileges in the ifrit.vl Domain. It designed for those with foundational AD and pentesting knowledge to hone covert red teaming skills. Players aim for Domain Admin while evading real-time detections, practicing AD enumeration, exploitation, certificate services, lateral movement, EDR bypass, and relay attacks across multiple forests.</description></item><item><title>VULNLAB: Vigilant</title><link>https://wearethebug.dev/posts/vl-vigilant/</link><pubDate>Mon, 15 Apr 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-vigilant/</guid><description>Vigilant is a Hard hybrid Active Directory chain. The environment consists of a domain-joined Linux system and a Windows Domain Controller, presenting a realistic enterprise attack surface. It designed to evaluate penetration testing capabilities in hybrid Windows-Linux environments. Participants begin with zero initial access and must systematically escalate privileges to achieve Domain Administrator-level compromise.</description></item><item><title>VULNLAB: Sendai</title><link>https://wearethebug.dev/posts/vl-sendai/</link><pubDate>Fri, 15 Mar 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-sendai/</guid><description>Sendai is a medium-difficulty Windows Active Directory machine focused on weak account hygiene, GMSA abuse, and ADCS misconfigurations. Initial access is gained through anonymous SMB enumeration, revealing files that hint at expired accounts with weak passwords. RID brute-forcing identifies users, and login attempts highlight accounts in a forced password reset state. By resetting thomas.powell’s password, the attacker obtains a domain foothold. BloodHound analysis shows that Powell’s group membership can be leveraged to compromise the MGTSVC$ GMSA account, enabling remote code execution on the domain controller. Further local enumeration uncovers inline credentials for clifford.davey, whose CA-OPERATORS group membership grants GenericAll rights over a certificate template. Abusing ESC4/ESC1 conditions with Certipy, the attacker forges a certificate for the administrator account, retrieves its NT hash, and authenticates via WinRM, achieving full domain compromise.</description></item><item><title>VULNLAB: Kaiju</title><link>https://wearethebug.dev/posts/vl-kaiju/</link><pubDate>Fri, 02 Feb 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-kaiju/</guid><description>Kaiju is a Hard-rated Active Directory chain, from initial reconnaissance to full domain compromise, covering FileZilla exploitation, KeePass database extraction, NTLM relay attacks, and ADCS abuse (ESC8).</description></item><item><title>VULNLAB: Retro</title><link>https://wearethebug.dev/posts/vl-retro/</link><pubDate>Fri, 11 Aug 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-retro/</guid><description>Retro is an Easy Windows machine that showcases an Active Directory Domain Controller. Through SMB enumeration and pre-created machine account exploitation, we gain access to the system. Through the exploitation of the Active Directory Certificate Service and specifically by using the ESC1 attack, which involves exploiting certificate templates to impersonate the Administrative user, privilege escalation is achieved.</description></item><item><title>VULNLAB: Hybrid</title><link>https://wearethebug.dev/posts/vl-hybrid/</link><pubDate>Thu, 22 Jun 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-hybrid/</guid><description>Hybrid is an Easy-rated, simplified Active Directory chain with 2 servers MAIL01 (Roundcube webmail) and DC01. Exploited a vulnerable Roundcube plugin via a crafted email, escalated privileges via NFS, and abused AD CS with certipy to achieve Domain Admin.</description></item><item><title>VULNLAB: Intercept</title><link>https://wearethebug.dev/posts/vl-intercept/</link><pubDate>Sat, 25 Dec 2021 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-intercept/</guid><description>Intercept is a small Active Directory scenario rated as Hard that provides hands-on experience with common Active Directory vulnerabilities and misconfigurations, demonstrating relay attacks and authentication coercion attacks can be used to get access to the domain.</description></item></channel></rss>