Certipy find (ADCS enum)
certipy find -u <user>@<domain> -p '<pass>' -dc-ip <dc-ip> -vulnerable
Enumerate ADCS (Active Directory Certificate Services) infrastructure and detect vulnerable templates.
When you have domain credentials and want to identify attack vectors via ADCS. Certipy find scans the domain PKI and reports templates with insecure configurations (ESC1-ESC13).
If the domain does not have ADCS installed (no certificate service). Also if the scan generates too many LDAP queries that could be detected by the SIEM.