title: ADCSPwn Hack Tool id: cd8c163e-a19b-402e-bdd5-419ff5859f12 description: Detects command line parameters used by ADCSPwn, a tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service status: test author: Florian Roth references: - https://github.com/bats3c/ADCSPwn date: 2021/07/31 tags: - attack.credential_access - attack.t1557.001 logsource: category: process_creation product: windows detection: selection: CommandLine|contains|all: - ' --adcs ' - ' --port ' condition: selection falsepositives: - Unlikely level: critical