Certipy auth
certipy auth -pfx administrator.pfx -dc-ip <dc-ip>
Use a PKCS#12 (.pfx) certificate to authenticate to the domain via Kerberos PKINIT.
After obtaining a .pfx certificate from a vulnerable template (ESC1), use certipy auth to get a TGT and authenticate as the impersonated account. This step converts the certificate into real domain access.
If the certificate has expired or is not valid for PKINIT authentication (does not have Extended Key Usage for Client Authentication).