Cypher: ADCS ESC1 Candidates (Certipy BloodHound)

List every user that can enroll in an ESC1-vulnerable certificate template (enrollee supplies subject + client authentication EKU + enabled). Requires the Certipy BloodHound data model — collect with `certipy find -bloodhound`.

Tool
MATCH
Category
Enumeration / BloodHound Cypher Queries
Platform
cross-platform
Requires
no credentials

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

MATCH (u:User)-[:Enroll]->(t:CertTemplate {`Enrollee Supplies Subject`:true, `Client Authentication`:true, `Enabled`:true}) RETURN u.name, t.name

Examples

MATCH (u:User)-[:Enroll]->(t:CertTemplate {`Enrollee Supplies Subject`:true, `Client Authentication`:true, `Enabled`:true}) RETURN u.name, t.name

Tags

bloodhound cypher certipy adcs esc1 graph

References