The definitive offensive reference for Active Directory Certificate Services.
Forged Trust is a book-length treatment of offensive operations against Active Directory Certificate Services (ADCS). It documents the complete attack taxonomy from first principles, covering every technique end to end — the misconfiguration’s root cause, its prerequisites, exploitation, and detection artifacts — alongside the KB5014754 enforcement landscape.
- Available on Amazon: Forged Trust: Offensive Operations against ADCS
What it covers
| Family | Range | Focus |
|---|---|---|
| ESC | ESC1 – ESC18 | Escalation via template and CA misconfigurations |
| THEFT | THEFT1 – THEFT5 | Credential and private-key theft |
| PERSIST | PERSIST1 – PERSIST3 | User-level certificate persistence |
| DPERSIST | DPERSIST1 – DPERSIST3 | Domain-level (CA) persistence |
Every technique is treated the same way — from the misconfiguration’s root cause through prerequisites, exploitation, and the detection artifacts a defender can hunt for — making the book both an offensive playbook and a defensive reference.
Related work
Forged Trust extends the systematization-of-knowledge whitepaper Certificate of Compromise into a complete, book-length reference. For direct correspondence, reach out on X at @thehackersbrain.
Written by Gaurav Raj (@thehackersbrain) ↗