This section serves as a quick reference for Certipy's commands, summarizing their purpose and usage. Use this as a cheat-sheet when operating Certipy during assessments or audits. Each command is invoked as a sub-command to `certipy`. Common global options like `-u/-p` (credentials), `-hashes`, `-dc-ip`, and `-debug` are omitted for brevity. ## Summary of Commands ### `account` **Manage AD user/computer accounts** Usage: `certipy account [create|read|update|delete] -user [options]` Key Flags: * `-group ` - Group to add the account to * `-dns ` - Set dNSHostName * `-upn ` - Set UserPrincipalName * `-sam ` - Set new SAM name * `-spns ` - Set SPNs * `-pass ` - Set password --- ### `auth` **Authenticate using a certificate** Usage: `certipy auth -pfx [options]` Key Flags: * `-password ` - PFX password * `-print` - Print TGT in kirbi format * `-kirbi` - Save as .kirbi * `-ldap-shell` - Start LDAP shell after auth --- ### `ca` **Manage CA templates and requests** Usage: `certipy ca -ca [options]` Key Flags: * `-list-templates` - List enabled templates * `-enable-template