ly4k/Certipy
PythonTool for Active Directory Certificate Services enumeration and abuse
pip install certipyCertipy - AD CS Attack & Enumeration Toolkit
Certipy is a powerful offensive and defensive toolkit for enumerating and abusing Active Directory Certificate Services (AD CS). It helps red teamers, penetration testers, and defenders assess AD CS misconfigurations - including full support for identifying and exploiting all known ESC1-ESC17 attack paths.
[!WARNING] Use only in environments where you have explicit authorization. Unauthorized use may be illegal.
π Features
- π Discover Certificate Authorities and Templates
- π© Identify misconfigurations
- π Request and forge certificates
- π Perform authentication using certificates
- π‘ Relay NTLM authentication to AD CS HTTP(S)/RPC endpoints
- ποΈ Support for Shadow Credentials, Golden Certificates, and Certificate Mapping Attacks
- π§° And much more!
π Full Wiki & Documentation
Read the full step-by-step usage guide, including installation, vulnerability explanations, examples, and mitigations in the π Certipy Wiki.
βοΈ Installation
See the Installation Guide for instructions on how to install Certipy.
π Quick Start
See the Quick Start Guide for a quick overview of the most common commands and usage examples.
π― Supported AD CS Vulnerabilities
Certipy supports detection and exploitation of AD CS vulnerabilities across the full range of ESC1-ESC17.
For detailed explanations and exploitation steps, refer to the Certipy Wiki.
π Resources
See the Resources for selection of key resources related to AD CS security.
π€ Contributing
Contributions are welcome! See CONTRIBUTING.md for guidelines on reporting issues, improving documentation, or submitting pull requests.
π Sponsors
Thanks to these generous sponsors for supporting the development of this project. Your contributions help sustain ongoing work and improvements.


π€ Author
Developed by @ly4k, with valuable contributions from the community.
π Wiki
π Visit the Certipy Wiki for detailed documentation, usage examples, ESC vulnerability breakdowns, and mitigation advice.