Certipy is an offensive and defensive toolkit for enumerating and abusing Active Directory Certificate Services misconfigurations.
The tool addresses the problem of assessing AD CS security posture by providing comprehensive enumeration and exploitation capabilities. It discovers Certificate Authorities and Templates, identifies misconfigurations, requests and forges certificates, and performs authentication using certificates. The toolkit supports detection and exploitation of all known ESC1-ESC17 attack paths, along with advanced techniques including Shadow Credentials, Golden Certificates, Certificate Mapping Attacks, and NTLM relay to AD CS HTTP(S) and RPC endpoints.
Red teamers and penetration testers assessing Active Directory environments should consider this tool when evaluating AD CS security. It suits engagements where comprehensive coverage of certificate-based attack vectors is needed, from initial enumeration through full exploitation chains. The project provides step-by-step usage guidance and detailed vulnerability explanations through its wiki documentation, making it accessible for both learning and operational use.
The project maintains an active contribution model with documented guidelines for reporting issues and submitting improvements. Development is supported by community contributions alongside the primary author's work.