Certipy is an open-source tool used for Active Directory discovery and abuse, particularly around Active Directory Certificate Services (AD CS) and collection of Active Directory-related credential and certificate data. In the provided reporting, Cisco Talos observed the China-linked threat actor UAT-8837 deploying Certipy during post-compromise activity against critical infrastructure organizations in North America since at least 2025. The actor used it alongside tools such as Rubeus, SharpHound, Impacket, GoExec, Earthworm, and DWAgent after gaining initial access via exploitation of vulnerable servers or use of compromised credentials, including in activity involving Sitecore vulnerability CVE-2025-53690. Talos specifically described Certipy as being used for AD discovery and abuse and for enumerating Active Directory users, groups, SPNs, service accounts, and domain relationships, as well as collecting Active Directory-related credential and certificate data. The reporting does not provide Certipy-specific indicators of compromise, but places its use within broader UAT-8837 intrusions involving credential harvesting, Kerberos abuse, remote execution, tunneling, and Active Directory reconnaissance.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Finally, I authenticated using the issued certificate... Authentication succeeded, allowing me to impersonate the Domain Administrator without ever knowing the Administrator’s password.
Add Shadow Credentials Same as before, we’ll create shadow credentials using Certipy: certipy-ad shadow auto ... Adding shadow creds to james account | Modify the UPN ... we’ll set it to a DC machine account — in this case, LAB-DC.LAB.LOCAL for Schannel certificate-based authentication. certipy-ad account update ... -upn 'lab-dc$@lab.local'
By default, most Active Directory domains allow authenticated users to create up to ten computer accounts. The exploit takes advantage of this default configuration by creating a machine account that the attacker legitimately owns.
A newly disclosed vulnerability in Active Directory Certificate Services (AD CS) demonstrates how a standard domain user can escalate privileges to complete Active Directory compromise by abusing a flaw in Microsoft’s certificate enrollment process.
Finally, I authenticated using the issued certificate... Authentication succeeded, allowing me to impersonate the Domain Administrator without ever knowing the Administrator’s password.
Add Shadow Credentials Same as before, we’ll create shadow credentials using Certipy: certipy-ad shadow auto ... Adding shadow creds to james account | Modify the UPN ... we’ll set it to a DC machine account — in this case, LAB-DC.LAB.LOCAL for Schannel certificate-based authentication. certipy-ad account update ... -upn 'lab-dc$@lab.local'
This method relies on the ability to obtain the user’s NTLM hash using the PKINIT mechanism... Got NT hash for 'administrator@contoso.com'
Once operating as a Domain Controller, the attacker inherits one of the most sensitive privileges within Active Directory: directory replication. That privilege enables DCSync, a technique that requests password data directly through the Directory Replication Service Remote Protocol rather than reading the NTDS database from disk.
Instead of first validating the destination, the CA attempted to communicate with the supplied host using SMB and LDAP. That design decision created the opportunity for attackers to position themselves directly inside the enrollment workflow.
If the certificate template lacks the required security extension (objectSid), and we control a user account, we can manipulate its attributes to request a certificate that gets mapped to a different identity, like a DA.
When the Certification Authority connects to the attacker-controlled host specified by the cdc attribute, those services participate in the enrollment process while relaying portions of the authentication flow to the legitimate Domain Controller using Netlogon.
Once that certificate has been issued, it can be used with Kerberos PKINIT authentication to obtain Domain Controller credentials, enabling DCSync attacks that expose the krbtgt account and effectively hand over control of the domain.
If an attacker obtains the krbtgt secret, they can forge Kerberos tickets that are trusted by every Domain Controller in the forest until the account password is reset appropriately. | Under specific deployment conditions, the CA can be convinced to issue a certificate containing the identity of a legitimate Domain Controller even though the request originated from an attacker-controlled machine.
Use the auth command to authenticate as administrator and grab the NT hash: certipy auth -pfx administrator.pfx -domain lab.local -dc-ip 10.129.228.236 ... Retrieved the Administrator NT hash
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An AD CS enumeration/abuse tool used to collect certificate-related data and facilitate credential access via certificate services misconfigurations.
A tool used for Active Directory discovery and abuse, particularly in certificate services contexts.
Tool for enumerating and abusing AD CS misconfigurations to escalate privileges and obtain persistence via certificate-based attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.