
SoK/Whitepaper on Offensive Operations against Active Directory Certificate Service
SoK/Whitepaper on Offensive Operations against Active Directory Certificate Service
This paper is a living document. ADCS research is not static — techniques get patched, new conditions are discovered, and community analysis refines the understanding of existing ones. As that happens, this paper will be updated: new techniques added, patch status entries revised, detection guidance corrected where better signal exists. Version history is tracked in the repository.
If you find an error — technical, factual, or typographical — please report it. Mistakes in a paper of this scope are inevitable. Open an issue or start a discussion.
Pull requests for corrections are welcome. For direct correspondence, the contact email is in the front matter of this paper, or reach out on X at @thehackersbrain.
This paper has also been submitted to arXiv cs.CR (pending endorsement). Established cs.CR authors willing to endorse can use this link: https://arxiv.org/auth/endorse?x=E68XML