Skip to main content

Certipy - AD CS Attack & Enumeration Toolkit

PyPI version Python License

Certipy is a powerful offensive and defensive toolkit for enumerating and abusing Active Directory Certificate Services (AD CS). It helps red teamers, penetration testers, and defenders assess AD CS misconfigurations - including full support for identifying and exploiting all known ESC1-ESC16 attack paths.

[!WARNING] Use only in environments where you have explicit authorization. Unauthorized use may be illegal.


🔍 Features

  • 🔎 Discover Certificate Authorities and Templates
  • 🚩 Identify misconfigurations
  • 🔐 Request and forge certificates
  • 🎭 Perform authentication using certificates
  • 📡 Relay NTLM authentication to AD CS HTTP(S)/RPC endpoints
  • 🗝️ Support for Shadow Credentials, Golden Certificates, and Certificate Mapping Attacks
  • 🧰 And much more!

📚 Full Wiki & Documentation

Read the full step-by-step usage guide, including installation, vulnerability explanations, examples, and mitigations in the 📘 Certipy Wiki.


⚙️ Installation

See the Installation Guide for instructions on how to install Certipy.


🚀 Quick Start

See the Quick Start Guide for a quick overview of the most common commands and usage examples.


🎯 Supported AD CS Vulnerabilities

Certipy supports detection and exploitation of AD CS vulnerabilities across the full range of ESC1-ESC16.

For detailed explanations and exploitation steps, refer to the Certipy Wiki.


📎 Resources

See the Resources for selection of key resources related to AD CS security.


🤝 Contributing

Contributions are welcome! See CONTRIBUTING.md for guidelines on reporting issues, improving documentation, or submitting pull requests.


🌟 Sponsors

Thanks to these generous sponsors for supporting the development of this project. Your contributions help sustain ongoing work and improvements.

User avatar: Henri SaloUser avatar: mxrch

👤 Author

Developed by @ly4k, with valuable contributions from the community.


📘 Wiki

📖 Visit the Certipy Wiki for detailed documentation, usage examples, ESC vulnerability breakdowns, and mitigation advice.

Metadata

Release files for certipy-ad 5.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for certipy-ad 5.1.0
File Size Uploaded
certipy_ad-5.1.0.tar.gz 155.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for certipy-ad 5.1.0
File Interpreter ABI Platform
certipy_ad-5.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 333.4 kB

Release files / certipy_ad-5.1.0.tar.gz

Download URL certipy_ad-5.1.0.tar.gz
Size 155.3 kB
Tags Source
SHA-256 checksum
How to use checksums
2b10b3a4e91f8aa1c7e403fef2ec5aa89d84a69e09e7e6e0602af3e036f4271e
BLAKE2b-256 checksum
How to use checksums
b67c84b900ca98998b06189cafc9c889f41fff64cc1857ad10dd1f9a50cf4f2e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.12

Release files / certipy_ad-5.1.0-py3-none-any.whl

Download URL certipy_ad-5.1.0-py3-none-any.whl
Size 178.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
0ff0d0b78cb1d83349d3ee93fafc2c870198cd36fc59a6d40f0827fe187b5077
BLAKE2b-256 checksum
How to use checksums
54f17a25f7a18518132191651e37a4df293960e5e347b60c32ac88f1f7ba2386
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.12

Release history Release notifications | RSS feed

This release

5.1.0 This release

2 release files

5.0.4

2 release files

5.0.3

2 release files

5.0.2

2 release files

5.0.1

2 release files

5.0.0

2 release files

4.8.2

2 release files

4.8.1

2 release files

4.8.0

2 release files

4.7.0

2 release files

4.6.0

2 release files

4.5.1

2 release files

4.5.0

2 release files

4.4.0

2 release files

4.3.0

2 release files

4.2.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page