Writing
active directory
3 articles on this subject.
Your certificate authority is an authentication system: ESC1, the SID extension, and what changed in 2025
ESC1 turns a low-privileged domain account into a domain admin certificate. Strong certificate mapping was supposed to end that, and since September 2025 it cannot be switched off. Here is what still works, what does not, and how to check your own templates.
8 min read
MFA succeeded and the account still fell: adversary-in-the-middle phishing and session cookie theft
The phishing chain that still works against companies with MFA switched on. A reverse proxy sits in front of the real login page, the victim authenticates for real, and the attacker keeps the session cookie.
7 min read
Active Directory is walked, not exploited: BloodHound edges, Kerberoasting and ADCS ESC1
Domain compromise is almost never a memory-corruption bug. It is a graph traversal across permissions somebody granted on purpose. Here are the three routes that keep working, and what to check tonight.
8 min read