Content area

Abstract

This thesis investigates critical cybersecurity vulnerabilities associated with Active Directory Certificate Services (ADCS), emphasizing attack vectors and defense strategies within enterprise environments. It specifically analyzes known attack scenarios, identified as ESC1 through ESC11, and the notable CERTIFIED vulnerability (CVE-2022-26923). To practically illustrate these threats, a detailed laboratory environment utilizing VMware Workstation 17.5 was established, incorporating Kali Linux for offensive testing and Windows Server systems representing a realistic ADCS infrastructure.

Through simulated attack scenarios utilizing the Certipy-ad toolkit, this research clearly demonstrates the significant risks posed by ADCS misconfigurations, ranging from privilege escalation to complete domain compromise. Embracing a Purple Team approach—collaboration between offensive (red) and defensive (blue) teams—enabled real-time detection, immediate feedback on attack effectiveness, and iterative improvements in defensive capabilities.

Moreover, this study outlines comprehensive defensive measures to mitigate identified vulnerabilities, including strict certificate template hardening, enforcement of CA administrative privilege management, and implementation of continuous monitoring solutions like Wazuh SIEM complemented by meticulous analysis of Windows Event Logs. The iterative Purple Teaming methodology significantly enhanced detection accuracy, response capabilities and overall resilience against ADCS-related threats.

Details

1010268
Title
A Purple Team Playbook Against Active Directory Certificate Services Attacks
Number of pages
118
Publication year
2025
Degree date
2025
School code
4463
Source
MAI 87/1(E), Masters Abstracts International
ISBN
9798290639109
Advisor
University/institution
University of Piraeus (Greece)
University location
Greece
Degree
M.Sc.
Source type
Dissertation or Thesis
Language
English
Document type
Dissertation/Thesis
Dissertation/thesis number
32130870
ProQuest document ID
3252742751
Document URL
https://www.proquest.com/dissertations-theses/purple-team-playbook-against-active-directory/docview/3252742751/se-2?accountid=208611
Copyright
Database copyright ProQuest LLC; ProQuest does not claim copyright in the individual underlying works.
Database
ProQuest One Academic