Privilege escalation from IIS AppPool to NT Authority/SYSTEM via AD CS RPC endpoint
Summary
A detailed blog post describing a Windows privilege escalation chain from IIS AppPool to the machine account on a domain via AD CS RPC endpoint. It explains how the IIS identity can be silently elevated to the machine account, enabling certificate-based TGT acquisition and S4U2Self impersonation to gain local Administrator access. The content includes step-by-step commands and screenshots, highlighting defensive considerations for AD CS abuse.