<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Adcs on Daniel Monzón - stark0de</title><link>https://stark0de.com/tags/adcs/</link><description>Recent content in Adcs on Daniel Monzón - stark0de</description><generator>Hugo</generator><language>en</language><copyright>&lt;a href="https://creativecommons.org/licenses/by-nc/4.0/" target="_blank" rel="noopener">CC BY-NC 4.0&lt;/a></copyright><lastBuildDate>Sat, 08 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://stark0de.com/tags/adcs/index.xml" rel="self" type="application/rss+xml"/><item><title>Certified Re-Pwned: escalating all the way up</title><link>https://stark0de.com/research/certified-re-pwned/</link><pubDate>Sat, 08 Aug 2026 00:00:00 +0000</pubDate><guid>https://stark0de.com/research/certified-re-pwned/</guid><description>Renaming the nomenclature: ESC1a, ESC1b, EAB1, and EAB2 At DEFCON 34 we presented five privilege escalation techniques in Active Directory Certificate Services, originally numbered ESC18 through ESC22. After the conference, and after discussing it with Oliver Lyak (the author of Certipy), we did two things: we renamed the techniques so their nomenclature reflects the family they belong to, and we dropped one of them — the original ESC19 — because it does not stand on its own.</description></item></channel></rss>