Skip to content
hackingtools.ai
Certipy

Certipy

Certipy is a free open-source toolkit for enumerating and assessing Active Directory Certificate Services (AD CS) in authorised pentests and labs.

0

0 upvotes · 0 downvotes

Pricing
Free
Platforms
LinuxWindowsmacOS
Licence
Open source
Reviewed
Last reviewed 1 October 2026

What it is

Certipy is a free open-source Python toolkit by Oliver Lyak (ly4k/Certipy on GitHub, also published as certipy-ad on PyPI) for working with Active Directory Certificate Services. In authorised assessments and labs it helps enumerate certificate authorities and templates, spot weak configurations, and test certificate-based authentication paths that defenders need to understand.

What it helps with

- Discovering CAs, templates and enrolment permissions inside an authorised AD CS deployment.
- Highlighting known ESC-class certificate template and CA misconfigurations for remediation evidence.
- Requesting and using certificates in scoped tests of PKINIT and certificate authentication.
- Supporting NTLM relay assessments against AD CS HTTP endpoints where rules of engagement allow.
- Exploring related techniques such as shadow credentials and golden-certificate style scenarios in lab or authorised purple-team work.
- Running cross-platform with Python tooling without a commercial licence for the core project.

Who it's for

Penetration testers, red teams and AD defenders who need a dedicated AD CS assessment tool as a peer to BloodHound and Impacket-based identity attack-path work, for authorised environments only.

Worth knowing

Certipy is free and open source. Primary repository: github.com/ly4k/Certipy; informational site: certipy.com; package name on PyPI is often certipy-ad. No solid official graphic logo was found on the project site; this listing uses the author's GitHub avatar as the best official asset. Authorised penetration testing, auditing and lab use only; the project's own guidance requires explicit authorisation.

← Back to directory