Skip to content

find: detect vulnerabilities across all principals, not just current user - #349

Open
a5ucanc wants to merge 4 commits into
ly4k:mainfrom
a5ucanc:feature/output-all-vulnerabilities-per-principal
Open

a5ucanc wants to merge 4 commits into
ly4k:mainfrom
a5ucanc:feature/output-all-vulnerabilities-per-principal

Conversation

@a5ucanc

@a5ucanc a5ucanc commented Jan 25, 2026 •

Copy link
Copy Markdown

Overview

Enhanced the find command's vulnerability detection to provide comprehensive attack surface analysis by identifying all exploitable principals per vulnerability, rather than limiting results to the current authenticated user.

fixes #353

Key Changes

Comprehensive Vulnerability Detection

  • Before: Vulnerabilities were only detected if exploitable by the current authenticated user
  • After: All vulnerabilities are detected with a list of principals who can exploit each one

New vulnerability output structure:

{
  "ESC1": {
    "description": "Enrollee supplies subject and template allows client authentication.",
    "principals": ["DOMAIN\\User1", "DOMAIN\\User2", "DOMAIN\\ITGroup"]
  }
}

Principal Filtering

To keep output focused on actionable findings, well-known privileged groups (Domain Admins, Enterprise Admins, etc.) are excluded from the principals list. Since these groups inherently have dangerous permissions over templates (write, owner, etc.), including them would add noise without meaningful attack surface insight. Only custom/non-default groups and users are listed.

@a5ucanc a5ucanc changed the title Enhanced vulnerability detection with per-principal exploitation tracking find: detect vulnerabilities across all principals, not just current user Mar 22, 2026
@ThatTotallyRealMyth

Copy link
Copy Markdown

I think this would be a solid addition : )

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] Certipy fails to detect Write access to template

2 participants