← All Lessons
Premium

TechniqueActive Directory

Relaying NTLM to AD CS Web Enrollment

Learn how NTLM relay attacks can target AD CS HTTP enrollment endpoints to obtain certificates for relayed identities, converting intercepted network authentication into long-lived certificate-based access that survives password resets.

Sign in or upgrade to unlock the full premium library.

What you'll learn

  • HTTP enrollment endpoint
  • Authentication coercion
  • Transient-to-durable conversion
  • Machine account certificates
  • Default template availability

What premium includes

  • All 68 lessons: AD techniques, professional skills, each with interview answers and study kits
  • Complete study kit for every lesson: quizzes, flashcards, and briefs
  • Every learning track with full structured progression
  • All 12 attack paths: full compromise walkthroughs for interviews and reports
  • New lessons and attack paths added regularly

Continue with free content

Relaying NTLM to AD CS Web Enrollment — ExplainTheHack