skip to content
Decrypt LOL

Get Cyber-Smart in Just 5 Minutes a Week

Decrypt delivers quick and insightful updates on cybersecurity. No spam, no data sharing—just the info you need to stay secure.

Read the latest edition

New Command Enhances Offline Active Directory Certificate Services Enumeration

/ 1 min read

🕵️‍♂️ New command enhances stealthy offline Active Directory Certificate Services enumeration. Researchers Cedric Van Bockhaven and Max Grim from Outflank have introduced a command that utilizes the local registry’s certificate template cache for offline enumeration of Active Directory Certificate Services (AD CS), circumventing traditional monitoring methods. This approach allows attackers and security professionals to gather information without triggering alerts typically associated with LDAP queries. The command integrates with existing analysis frameworks, enabling users to parse registry data and assess certificate templates while minimizing detection risks. Future challenges include obtaining valid certificates without raising alarms, highlighting the ongoing cat-and-mouse game between attackers and defenders in cybersecurity.

Source
{entry.data.source.title}
Original