Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
PSPKIAudit — PowerShell toolkit for AD CS auditing based on the PSPKI toolkit. | Kitploit
Tools/GitHubGitHub/ghostpack/pspkiaudit
Privilege EscalationPenetration Testing
GitHubghostpack/pspkiaudit

PSPKIAudit

PowerShell toolkit for AD CS auditing based on the PSPKI toolkit.

View Repository
941130572 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

PSPKIAudit

PowerShell toolkit for auditing Active Directory Certificate Services (AD CS).

It is built on top of PKISolution's PSPKI toolkit (Microsoft Public License). This repo contains a newer version of PSPKI than what's available in the PSGallery (see the PSPKI directory). Vadims Podans (the creator of PSPKI) graciously provided this version as it contains patches for several bugs.

This README is only meant as a starting point- for complete details and defensive guidance, please see the "Certified Pre-Owned" whitepaper.

The module contains the following main functions:

  1. Invoke-PKIAudit - Audits the current Forest's AD CS settings, primarily analyzing the CA server and published templates for potential privilege escalation opportunities.
  2. Get-CertRequest - Examines a CA's issued certificates by querying the CA's database. Primary intention is to discover certificate requests that may have abused a certificate template privilege escalation vulnerability. In addition, if a user or computer is compromised, incident responders can use it to find certificates the CA server had issued to the compromised user/computer (which should then be revoked).

WARNING: This code is beta! We are confident that Invoke-PKIAudit will not impact the environment as the amount of data it queries is quite limited. We have not done rigorous testing with Get-CertRequest against typical CA server workloads. Get-CertRequest queries the CA's database directly and may have to process thousands of results, which might impact performance.

IF THERE ARE NO RESULTS, THIS IS NOT A GUARANTEE THAT YOUR ENVIRONMENT IS SECURE!!

WE ALSO CANNOT GUARANTEE THAT OUR MITIGATION ADVICE WILL MAKE YOUR ENVIRONMENT SECURE OR WILL NOT DISRUPT OPERATIONS!

It is your responsibility to talk to your Active Directory/PKI/Architecture team(s) to determine the best mitigations for your environment.

If the code breaks, or we missed something, please submit an issue or pull request for a fix!

  • Setup
  • Auditing AD CS Misconfigurations
    • Output Explanation
    • ESC1 - Misconfigured Certificate Templates
    • ESC2 - Misconfigured Certificate Templates
    • ESC3 - Misconfigured Enrollment Agent Templates
    • ESC4 - Vulnerable Certificate Template Access Control
    • ESC5 - Vulnerable PKI AD Object Access Control
    • ESC6 - EDITF_ATTRIBUTESUBJECTALTNAME2
    • ESC7 - Vulnerable Certificate Authority Access Control
    • ESC8 - NTLM Relay to AD CS HTTP Endpoints
    • Misc - Explicit Mappings
  • Triaging Existing Issued Certificate Requests

Setup

Requirements

Install the following on a Windows machine using an elevated PowerShell prompt (PowerShell verion 5.1 or above):

  • RSAT's Certificate Services and Active Directory features. Install with the following command:
Get-WindowsCapability -Online -Name "Rsat.*" | where Name -match "CertificateServices|ActiveDirectory" | Add-WindowsCapability -Online
  • The PSPKI PowerShell module. Install with the following command:
Install-Module -Name PSPKI

Import

Download the module extract it to a folder. Then, import the module using the following commands:

cd PSPKIAudit
Get-ChildItem -Recurse | Unblock-File

Import-Module .\PSPKIAudit.psd1

Auditing AD CS Misconfigurations

Running Invoke-PKIAudit will run all auditing checks against AD CS in the current domain, including enumerating various Certificate Authority and Certificate Template settings. To audit a specific CA, you can run Invoke-PKIAudit -CAComputerName CA.DOMAIN.COM or Invoke-PKIAudit -CAName X-Y-Z.

Any misconfigurations (ESC1-8) will appear as properties on the CA/template results displayed to identify the specific misconfiguration found.

If you want to change the groups/users used to test enrollment/access control, modify the $CommonLowprivPrincipals regex at the top of Invoke-PKIAudit.ps1

If you want to export all CA information to a csv, run: Get-AuditCertificateAuthority [-CAComputerName CA.DOMAIN.COM | -CAName X-Y-Z] | Export-Csv -NoTypeInformation CAs.csv

If you want to export ALL published template information to a csv (not just vulnerable templates), run: Get-AuditCertificateTemplate [-CAComputerName CA.DOMAIN.COM | -CAName X-Y-Z] | Export-Csv -NoTypeInformation templates.csv

Output Explanation

There are two main sections of output, details about discovered CAs and details about potentially vulnerable templates.

For certificate authority results:

Certificate Authority PropertyDescription
ComputerNameThe system the CA is running on.
CANameThe name of the CA.
ConfigStringThe full COMPUTER\CA_NAME configuration string.
IsRootIf the CA is a root CA.
AllowsUserSuppliedSansIf the CA has the EDITF_ATTRIBUTESUBJECTALTNAME2 flag set.
VulnerableACLWhether the CA has a vulnerable ACL setting.
EnrollmentPrincipalsPrincipals who have the Enroll privilege at the CA level.
EnrollmentEndpointsThe CA's web services enrollment endpoints.
NTLMEnrollmentEndpointsThe CA's web services enrollment endpoints that have NTLM enabled.
DACLThe full access control information.
MisconfigurationsESCX indicating the specific misconfiguration present (if any).

For certificate template results:

Download Tool