INTEL_REPORT
Palo Alto Networks Unit 42 · published 5/11/2026, 10:00:43 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools Unit 42 analyzes AD CS exploitation through template misconfigurations and shadow credential misuse while offering behavioral detection for defenders. The post Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools appeared first on Unit 42 . Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Researc…
https://unit42.paloaltonetworks.com/active-directory-certificate-services-exploitation
sha256:0b0e8ecb41a070526d1131692ca3a5ea4fe37a28dc10e9d2c4fd76123fb61c27
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.