██▀▀▀▀▀█ ██▀▀▀▀▀█ ██▀▀▀▀▀█ ██▀▀▀▀▀█ ██   ▄▄▀ ██▀▀▀▀▀█
      ▒█ ▒█▀▀▀ ▒█ ▒█    ▒█ ▒█▀▀▀ ▒█ ▒█▀▀▀▀▄  ▒█▀▀▀ ▒█
      ▓▓ ▓▓    ▓▓ ▓▓    ▓▓ ▓▓    ▓▓ ▓▓    ▓▓ ▓▓    ▓▓
      █▒ █▒    █▒ █▒    █▒ █▒    █▒ █▒    █▒ █▒    █▒
      ▓░ ▓░    ▓░ ▓░    ▓░ ▓░    ▓░ ▓░    ▓░ ▓░    ▓░
      ▒█ ▒█    ▒█ ▒█    ▒█ ▒█    ▒█ ▒█    ▒█ ▒█    ▒█
      ░▓ ░▓    ░▓ ░▓    ░▓ ░▓    ░▓ ░▓    ░▓ ░▓    ░▓
       ▒  ▒     ▒  ▒     ▒  ▒     ▒  ▒     ▒  ▒     ▒
      ▀▀ ▀▀    ▀▀ ▀▀    ▀▀ ▀▀    ▀▀ ▀▀    ▀▀ ▀▀    ▀▀

tanaka | @tanakz

offensive security researcher.

welcome to my zone! here, i share some research and studies on cybersecurity. :)

latest post: From ESC4 to Domain Admin: exploiting vulnerable templates in AD CS

Active Directory Certificate Services (AD CS) is one of the most powerful technologies, and when misconfigured, one of the most dangerous within an AD environment. In this article, I will cover a scenario I came across during my AD studies, involving an exploitation chain involving ESC4 -> ESC1.

> read more

articles: