Episode 6 - ADCS: your greatest ally or biggest vulnerability? episode artwork

EPISODE · Mar 2, 2026 · 47 MIN

Episode 6 - ADCS: your greatest ally or biggest vulnerability?

from The Zero Trust Zone · host Michael Van Horenbeeck

Certificates are either your strongest authentication control or your biggest hidden liability.In Episode 6 of The Zero Trust Zone, I’m joined by identity expert Jake Hildreth to unpack the real-world security implications of Active Directory Certificate Services (AD CS).We discuss why PKI is often misunderstood, how certificate misconfigurations become high-impact attack paths, and how tools like Locksmith are helping organizations identify exposure before attackers do.From Zero Trust architecture to ESC abuse paths, this episode dives deep into the sense (and some nonsense) of certificates in modern enterprise security.Topics covered include:Why AD CS has become a prime attack surfaceCommon certificate misconfigurations in enterprise environmentsESC vulnerabilities explainedProactive PKI auditing and hardening strategiesResources mentioned:SpecterOps – Certified Pre-Owned: Abusing Active Directory Certificate Serviceshttps://posts.specterops.io/certified-pre-owned-d95910965cd2Jake Hildreth – LockSmith PowerShell Toolkithttps://github.com/jakehildreth/LocksmithMichael Waterman – Top 10 PKI Recommendations by a Former Microsoft Security Engineerhttps://michaelwaterman.nl/2026/02/15/top-10-pki-recommendations-by-a-former-microsoft-security-engineer/

Certificates are either your strongest authentication control or your biggest hidden liability.In Episode 6 of The Zero Trust Zone, I’m joined by identity expert Jake Hildreth to unpack the real-world security implications of Active Directory Certificate Services (AD CS).We discuss why PKI is often misunderstood, how certificate misconfigurations become high-impact attack paths, and how tools like Locksmith are helping organizations identify exposure before attackers do.From Zero Trust architecture to ESC abuse paths, this episode dives deep into the sense (and some nonsense) of certificates in modern enterprise security.Topics covered include:Why AD CS has become a prime attack surfaceCommon certificate misconfigurations in enterprise environmentsESC vulnerabilities explainedProactive PKI auditing and hardening strategiesResources mentioned:SpecterOps – Certified Pre-Owned: Abusing Active Directory Certificate Serviceshttps://posts.specterops.io/certified-pre-owned-d95910965cd2Jake Hildreth – LockSmith PowerShell Toolkithttps://github.com/jakehildreth/LocksmithMichael Waterman – Top 10 PKI Recommendations by a Former Microsoft Security Engineerhttps://michaelwaterman.nl/2026/02/15/top-10-pki-recommendations-by-a-former-microsoft-security-engineer/

NOW PLAYING

Episode 6 - ADCS: your greatest ally or biggest vulnerability?

0:00 47:18

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Frequently Asked Questions

How long is this episode of The Zero Trust Zone?

This episode is 47 minutes long.

When was this The Zero Trust Zone episode published?

This episode was published on March 2, 2026.

What is this episode about?

Certificates are either your strongest authentication control or your biggest hidden liability.In Episode 6 of The Zero Trust Zone, I’m joined by identity expert Jake Hildreth to unpack the real-world security implications of Active Directory...

Can I download this The Zero Trust Zone episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!