Cypher: ADCS ESC1 Candidates (Certipy BloodHound)
List every user that can enroll in an ESC1-vulnerable certificate template (enrollee supplies subject + client authentication EKU + enabled). Requires the Certipy BloodHound data model — collect with `certipy find -bloodhound`.
- Tool
- MATCH
- Category
- Enumeration / BloodHound Cypher Queries
- Platform
- cross-platform
- Requires
- no credentials
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
MATCH (u:User)-[:Enroll]->(t:CertTemplate {`Enrollee Supplies Subject`:true, `Client Authentication`:true, `Enabled`:true}) RETURN u.name, t.name
Examples
MATCH (u:User)-[:Enroll]->(t:CertTemplate {`Enrollee Supplies Subject`:true, `Client Authentication`:true, `Enabled`:true}) RETURN u.name, t.name
Tags
References
Related commands
- BloodHound.py CE Collector Collect AD data into the BloodHound Community Edition JSON format from Linux. Use --zip…
- Cypher: All Paths from Owned to High-Value All shortest paths from any owned principal to any high-value target (Domain Admins,…
- Cypher: AS-REP Roastable Users List every user with DONT_REQ_PREAUTH set — these accounts can be AS-REP roasted without…
- Cypher: Kerberoastable Users List every kerberoastable user in the domain (has a SPN, not krbtgt). Pair with hasLAPS…
- Cypher: Principals With DCSync Rights Find every principal that holds DS-Replication-Get-Changes /…
- Cypher: RBCD Write Targets Surface every account that can write to a computer object — the precondition for…
- Cypher: Shortest Path to Domain Admins Find the shortest attack path from any owned user to the Domain Admins group. The…
- Cypher: Unconstrained Delegation Find every computer or user with TRUSTED_FOR_DELEGATION set, excluding the DCs…