ESC13 — Issuance Policy OID Group Link
External: Hacker Recipes — ESC13
External: Internal All The Things — Certificate ESC13
Idea: Certificate template linked to issuance policy OID → OID linked to AD group → control group membership → gain enrollment rights → often chains to ESC1-style abuse.
Detect
grep -i ESC13 *_Certipy.txt
# Certipy shows Issuance Policy / OID group linksExploit
- Add yourself to linked group (if you have rights) or abuse existing enrollment
- Request cert per template flags — usually ESC1 if SAN allowed