ESC13 — Issuance Policy OID Group Link

External: Hacker Recipes — ESC13

External: Internal All The Things — Certificate ESC13

Idea: Certificate template linked to issuance policy OID → OID linked to AD group → control group membership → gain enrollment rights → often chains to ESC1-style abuse.

Detect

grep -i ESC13 *_Certipy.txt
# Certipy shows Issuance Policy / OID group links

Exploit

  1. Add yourself to linked group (if you have rights) or abuse existing enrollment
  2. Request cert per template flags — usually ESC1 if SAN allowed

AD CS ESC · Certipy & Certify