ly4k/certipy

Tool for Active Directory Certificate Services enumeration and abuse

View on GitHub ↗Jump to charts ↓

Summary Information

Updated 24 minutes ago
Added to GitGenius on September 18th, 2026
Created on October 6th, 2021
Open Issues & Pull Requests: 25 (+0)
GitHub issues: Enabled
Number of forks: 483
Total Stargazers: 3,672 (+0)
Total Subscribers: 35 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 3.9 days
Mean response time: 124.8 days
90th percentile: 512.8 days
Tracked items: 109

Most active contributors

Sign in to see contributor activity.

How this project is maintained

Work labelled "user error" is answered fastest, typically in about 11 hours, while "rtm" waits about 3 weeks. Three people close 88% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 14
New in 7 days: 0
Closed in 7 days: 0
Avg open age: 277 days
Stale 30+ days: 14
Stale 90+ days: 11

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • bug (26)
  • stale (19)
  • help wanted (15)
  • user error (15)
  • rtm (13)
  • enhancement (10)
  • unreproducible (8)
  • question (7)

Most active issues this week

No issue events were indexed in the last 7 days.

Detailed Description

Certipy is an offensive and defensive toolkit for enumerating and abusing Active Directory Certificate Services misconfigurations.

The tool addresses the problem of assessing AD CS security posture by providing comprehensive enumeration and exploitation capabilities. It discovers Certificate Authorities and Templates, identifies misconfigurations, requests and forges certificates, and performs authentication using certificates. The toolkit supports detection and exploitation of all known ESC1-ESC17 attack paths, along with advanced techniques including Shadow Credentials, Golden Certificates, Certificate Mapping Attacks, and NTLM relay to AD CS HTTP(S) and RPC endpoints.

Red teamers and penetration testers assessing Active Directory environments should consider this tool when evaluating AD CS security. It suits engagements where comprehensive coverage of certificate-based attack vectors is needed, from initial enumeration through full exploitation chains. The project provides step-by-step usage guidance and detailed vulnerability explanations through its wiki documentation, making it accessible for both learning and operational use.

The project maintains an active contribution model with documented guidelines for reporting issues and submitting improvements. Development is supported by community contributions alongside the primary author's work.