Certipy req ESC1

certipy req -u <user>@<domain> -p '<pass>' -ca '<ca-name>' -template <vuln-template> -upn administrator@<domain>

Request a certificate from a vulnerable template (ESC1) for an administrator account (upn), allowing authentication as that account.

When Certipy find has identified a template with ESC1 (allows requesting certificates with user-specified SAN and exportable key). Use -upn to request the certificate as Domain Administrator.

If the template does not have 'Enrollment Rights' for your user, the attack will fail. Also not if the CA (Certificate Authority) requires manual approval of requests.