Skip to content
#

esc1

Here are 2 public repositories matching this topic...

Language: All
Filter by language

Build-it-then-break-it Active Directory lab: one `vagrant up` provisions a Domain Controller, Enterprise CA, Windows 10 and Kali on libvirt/KVM, then you exploit AD CS ESC1 end-to-end (enumerate → cert-as-admin → PKINIT → DCSync). Learn how a pentest really works by building the target and breaking it.

  • Updated Jun 22, 2026
  • PowerShell

Improve this page

Add a description, image, and links to the esc1 topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the esc1 topic, visit your repo's landing page and select "manage topics."

Learn more