Will Schroeder
- Co-created BloodHound with Andy Robbins and Rohan Vazarkar
- Co-authored the Certified Pre-Owned research on Active Directory Certificate Services abuse
- Author of PowerView and other widely used AD enumeration tooling
Bio
Will Schroeder co-created BloodHound and has published a long run of Active Directory research, including the Certified Pre-Owned work on Active Directory Certificate Services abuse and the PowerView enumeration tooling that preceded it.
Profile built from public project, research, and company records.
Where their work shows up
The AD CS research is the clearest example of the pattern: a component almost every enterprise ran, almost nobody audited, and which could be abused to mint authentication certificates for any user. It turned an unconsidered piece of internal PKI into a first-tier identity risk overnight. See AD CS certificate template abuse, Kerberoasting, and the ITDR guide.
Related on Start with Identity
- BlogA FreeIPA flaw chain let an anonymous client write itself a reusable administrator credential
CVE-2026-76578 (CVSS 9.8) chains with a 389 Directory Server ownership-check bug so an unauthenticated client can create an OTP token entry, pass the ownership
- CVECheckSum, Kerberos S4U missing cryptographic step
The KDC skipped a cryptographic step in PA-S4U-X509-USER (CWE-325). An attacker can forge an identity via S4U2self and escalate to domain compromise. Presented
- GlossaryIdentity Resilience
The ability to keep authenticating and authorising legitimate users, and to recover the identity system itself, when the identity provider or directory is degra
- CVEKerberLoss, invisible-Unicode SPN uniqueness bypass
Active Directory treated look-alike SPNs with invisible Unicode as unique. An attacker can hijack a service name, force NTLM downgrade, and steal credentials. S
- BlogKerberLoss: invisible Unicode lets an attacker twin a Kerberos SPN
CVE-2026-25177, CVSS 8.8. Active Directory treated look-alike SPNs as unique. Semperis and Shai Laron showed how that becomes service hijack and NTLM downgrade.
- CVEResetNightmare, kpasswd bypasses PAC_REQUESTOR_SID
Kerberos Change Password (kpasswd) did not honor PAC_REQUESTOR_SID the way the rest of AD did. A low-privilege user who can write their UPN can reset a Domain A