The Aftermath Part 4: The Vendor Requirement
By Red Siege | June 2, 2025
by Jason Downey
The final entry in The Aftermath blog series. At this point, I had successfully social engineered credentials, bypassed multifactor authentication, and established command and control within my client’s environment. In this last entry, we’ll discuss how I leveraged a vendor requirement to escalate to Domain Admin.
Active Directory Certificate Services (AD CS, not ADCS, by the way) has been one of my favorite things to exploit over the past year. Since the folks at SpecterOps released their research on AD CS, it has led to more Domain Admin escalations than any other method in my arsenal. This environment became yet another notch on my belt.
Using Certify, I identified a certificate template that allowed the requesting user to supply its own Enrollee Name—meaning I could specify any username I wanted to receive a valid certificate for. If I wanted to be Batman, I could request a certificate as Batman. I just wanted to be Domain Admin—so that’s exactly what I did.
This misconfigured template instantly granted me Domain Admin privileges. Any attacker with network access and knowledge of this flaw could have done the same.
When I informed the client that I had escalated to Domain Admin, they were flabbergasted. They didn’t even know what that certificate template was for. After some digging, they realized it was required by a third-party vendor’s product. The vendor’s installation guide had instructed them to configure it this way, and they had simply trusted that it was safe.
After further discussion, it became clear that the vendor had no real understanding of AD CS security—they just knew they needed to use it. Their requirement for allowing users to supply their own Enrollee Name wasn’t even necessary.
Trusting a vendor to provide a secure solution had left the entire organization open to complete compromise. AD CS misconfigurations are far too easy to accidentally set up—and even easier to exploit once discovered.
Thanks for following along with this series. Hopefully, you’ve learned something that can help better secure your own environment against some of the attacks we have the most success with.
About Jason Downey, Security Consultant

Jason Downey has over ten years of professional experience in IT and information security ranging in a variety of roles in network security roles with additional experience in systems administration. Jason has spoken in front of various audiences ranging from youth initiatives to major security conferences, while creating informational content on SiegeCasts and forward-facing marketing channels. Jason excels at a variety of penetration testing tactics and is well known for his vishing and social engineering expertise.
Certifications:
CRTO, GPEN, GCIH, CCNA R&S, CCNA Security, CEH, CHFI
Related Stories
View MoreBy Red Siege | September 3, 2026
by Justin Palk A couple of years ago, I put together a series on standing up a simple Windows AD domain in a lab environment. This article is part of […]
Learn MoreBy Red Siege | August 13, 2026
by Justin Palk A couple of years ago, I put together a series on standing up a simple Windows AD domain in a lab environment. This article is part of […]
Learn MoreBy Red Siege | July 7, 2026
by Justin Palk A couple of years ago, I put together a series on standing up a simple Windows AD domain in a lab environment. This is the start of […]
Learn More