A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.
-
Updated
Sep 1, 2026 - PowerShell
A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.
ACME Proxy enhancing your existing Certificate Authority Infrastructure
An AD CS toolkit for AD Admins, Defensive Security Professionals, and Filthy Red Teamers
NetBird fork adding Windows pre-login Machine Tunnel for Active Directory and Kerberos environments using mTLS machine certificates.
Internal PKI lab using AD Certificate Services with certificate templates, HTTPS binding in IIS, and automated trust for domain clients.
A simple explanation covering Active Directory from a macro/high-level overview.
A comprehensive collection of **18 production-ready PowerShell solutions** for Windows Server environments, covering Active Directory, Certificate Services, Hyper-V, DNS, DHCP, and more. Built with enterprise security, compliance, and scalability in mind.
Educational Active Directory exploitation and defence guide covering enumeration, credential access, privilege escalation, lateral movement, persistence, detection and hardening.
Full kill-chain pentest against GOAD — AS-REP roasting, Kerberoasting, constrained-delegation abuse, DCSync and Golden Ticket. Three independent paths to Domain Admin on north.sevenkingdoms.local. 41 findings mapped to MITRE ATT&CK with detection signals and mitigations. Graduation thesis.
PowerShell tools for AD CS and EJBCA/MSAE PKI: bulk template validity updates (SC-081), batch CSR submission with resume-safe tracking and tamper-resistant delivery, cross-forest template sync (target needs no CA), and offline enrollment-policy (CEP) setup per machine or via GPO. Field-validated with EJBCA; Pester-tested on PowerShell 5.1 & 7.
Enterprise hardening guide for Windows Server 2022/2025 and Active Directory, covering privileged access, Windows LAPS, Kerberos, LDAP, Group Policy, auditing, AD CS, backup, and forest recovery.
Single-file, dependency-free PowerShell auditor for Active Directory Certificate Services (AD CS) ESC misconfigurations. Read-only; run it straight from a domain-joined management server.
My blog.
Deployed a standalone Root CA on Windows Server 2012 R2 using AD CS. PKI configuration with production trade-off analysis
Windows Server lab demonstrating AD CS Enterprise Root CA deployment, certificate templates, GPO auto-enrollment, certificate revocation and CRL validation, and Web Enrollment.
Two-site MSP-style Active Directory forest as Ansible IaC on KVM/libvirt: Server 2025 DCs, Win 11 + Ubuntu members, cross-site replication, DHCP failover, and rehearsed DR.
To associate your repository with the ad-cs topic, visit your repo's landing page and select "manage topics."