Skip to content
Cybercraft Labs

Forged Trust: Offensive Operations against ADCS

The definitive offensive reference for Active Directory Certificate Services. Forged Trust documents the complete ADCS attack taxonomy from first principles — ESC1–ESC18, THEFT1–THEFT5, PERSIST1–PERSIST3, and DPERSIST1–DPERSIST3 — each technique covered end to end alongside the KB5014754 enforcement landscape.

Gaurav Raj (@thehackersbrain)1 minBook

The definitive offensive reference for Active Directory Certificate Services.

Forged Trust is a book-length treatment of offensive operations against Active Directory Certificate Services (ADCS). It documents the complete attack taxonomy from first principles, covering every technique end to end — the misconfiguration’s root cause, its prerequisites, exploitation, and detection artifacts — alongside the KB5014754 enforcement landscape.

What it covers

Family Range Focus
ESC ESC1 – ESC18 Escalation via template and CA misconfigurations
THEFT THEFT1 – THEFT5 Credential and private-key theft
PERSIST PERSIST1 – PERSIST3 User-level certificate persistence
DPERSIST DPERSIST1 – DPERSIST3 Domain-level (CA) persistence

Every technique is treated the same way — from the misconfiguration’s root cause through prerequisites, exploitation, and the detection artifacts a defender can hunt for — making the book both an offensive playbook and a defensive reference.

Forged Trust extends the systematization-of-knowledge whitepaper Certificate of Compromise into a complete, book-length reference. For direct correspondence, reach out on X at @thehackersbrain.

Want this testedin your environment?

The techniques above are the ones we use on engagements. Forty-five minutes with an engineer will tell you whether your estate is exposed to them.

Book the call