certipy find -dc-ip $DCIP -u $USER@$DOMAIN -p $PASSWORD -vulnerable -stdout certipy find -k -target $DC -vulnerable -stdout

Enumerate and abuse AD CS with Certipy (ESC1 / ESC7 / ESC9 / shadow).

Command: Linux

References:

https://github.com/ly4k/Certipy