← All Lessons
Premium

TechniqueActive Directory

Coercion to ADCS Web Enrollment Relay (ESC8)

ESC8 chains authentication coercion with NTLM relay to turn an unauthenticated machine on the network into a domain certificate the attacker controls. This lesson explains why the web enrollment endpoint is relayable, what the attacker gains, and how to communicate the risk clearly in interviews, reports, and stakeholder conversations.

Sign in or upgrade to unlock the full premium library.

What you'll learn

  • Web enrollment endpoint
  • Authentication coercion
  • NTLM relay
  • Client authentication certificate
  • PKINIT to NT hash

What premium includes

  • All 68 lessons: AD techniques, professional skills, each with interview answers and study kits
  • Complete study kit for every lesson: quizzes, flashcards, and briefs
  • Every learning track with full structured progression
  • All 12 attack paths: full compromise walkthroughs for interviews and reports
  • New lessons and attack paths added regularly

Continue with free content