2026-09-21 08:29 UTC
Not sure if its already part of the usual honeypot/canary toolkits but building some AD CS based canary (e.g. tailored to ESC1) should be pretty simple, shouldnt it? Like, set up a vulnerable template, prevent actual use (not sure if possible with default AD CS tooling, but definitely possible with TameMyCerts or something like it), nuke on use?
Replies (1)
-
@nyanbinary@infosec.exchange 2026-09-21 11:21
oh neat, @balthasar@infosec.exchange already built exactly that! https://github.com/srlabs/Certiception/tree/main