
Certipy
Certipy is a free open-source toolkit for enumerating and assessing Active Directory Certificate Services (AD CS) in authorised pentests and labs.
0 upvotes · 0 downvotes
- Category
- Offensive Security & Pentesting
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- Licence
- Open source
- Reviewed
- Last reviewed 1 October 2026
What it is
Certipy is a free open-source Python toolkit by Oliver Lyak (ly4k/Certipy on GitHub, also published as certipy-ad on PyPI) for working with Active Directory Certificate Services. In authorised assessments and labs it helps enumerate certificate authorities and templates, spot weak configurations, and test certificate-based authentication paths that defenders need to understand.
What it helps with
- Discovering CAs, templates and enrolment permissions inside an authorised AD CS deployment.
- Highlighting known ESC-class certificate template and CA misconfigurations for remediation evidence.
- Requesting and using certificates in scoped tests of PKINIT and certificate authentication.
- Supporting NTLM relay assessments against AD CS HTTP endpoints where rules of engagement allow.
- Exploring related techniques such as shadow credentials and golden-certificate style scenarios in lab or authorised purple-team work.
- Running cross-platform with Python tooling without a commercial licence for the core project.
Who it's for
Penetration testers, red teams and AD defenders who need a dedicated AD CS assessment tool as a peer to BloodHound and Impacket-based identity attack-path work, for authorised environments only.
Worth knowing
Certipy is free and open source. Primary repository: github.com/ly4k/Certipy; informational site: certipy.com; package name on PyPI is often certipy-ad. No solid official graphic logo was found on the project site; this listing uses the author's GitHub avatar as the best official asset. Authorised penetration testing, auditing and lab use only; the project's own guidance requires explicit authorisation.