What Is the Doom Tool? A Python TUI for Auditing AD CS Certificate Templates

Doom is a Python-based Textual TUI application that automates the discovery and inspection of Active Directory Certificate Services (AD CS) certificate templates, translating raw LDAP data into an interactive, human-readable interface for security auditors.

The Doom tool, developed in the 000pp/doom repository, provides security professionals with a streamlined way to identify misconfigurations in AD CS environments. By combining LDAP enumeration with an intuitive terminal interface, it eliminates the manual effort required to decode complex certificate template attributes.

How the Doom Tool Works: Core Architecture

Doom follows a three-stage pipeline: LDAP discovery, template enumeration, and attribute parsing. Each stage is implemented as a dedicated Python module within the src/doom/ directory.

LDAP Discovery and Connection

The tool establishes connectivity to Active Directory using an LDAP bind operation. The connection logic, implemented in src/doom/protocols/ldap.py, automatically handles the transition from plain LDAP to LDAPS (LDAP over SSL) when necessary. It locates the Certificate Templates container within the AD configuration partition, which serves as the starting point for all subsequent queries.

Template Enumeration

Once connected, Doom executes an LDAP subtree search for objects of class pKICertificateTemplate. The enumeration logic in src/doom/modules/enumerate_templates.py collects every attribute of each template, including binary blobs, bit-flags, and object identifiers (OIDs) that define certificate issuance policies.

Attribute Parsing and Decoding

Raw LDAP values are transformed into human-readable strings by src/doom/parsers/attribute.py. This module decodes flag enums from Certipy, translates OIDs into descriptive names, and formats Windows FILETIME values into standard timestamps. For binary time values, src/doom/parsers/filetime.py provides the low-level conversion logic.

Interactive Textual User Interface

Doom leverages the Textual library to provide a three-screen interface that guides users from authentication through data exploration.

LoginScreen

The entry point src/doom/screens/login_screen.py presents input fields for the LDAP host, domain, username, and password. This screen validates that all required credentials are present before proceeding to the connection phase.

LoadingScreen

Implemented in src/doom/screens/loading_screen.py, this screen performs the asynchronous LDAP bind operation while displaying a progress indicator. It handles connection errors and, upon success, forwards the active LDAP session to the main exploration screen.

MainScreen

The primary interface in src/doom/screens/main_screen.py renders a tree view of all discovered certificate templates. Expanding any node lazily loads and displays the parsed attributes, allowing auditors to inspect enrollment flags, manager approval requirements, and private key settings without overwhelming the initial view.

Installing and Running the Doom Tool

Doom is distributed as a Python package installable via pip or pipx. Once installed, launch the TUI by executing the doom command or running the module directly.


# Install using pipx (recommended for CLI tools)

pipx install git+https://github.com/000pp/doom.git

# Launch the interactive interface

doom

The program opens a terminal interface prompting for domain controller IP, domain name, username, and password, then displays the certificate template tree.

Programmatic Usage Examples

While designed as a TUI, Doom's core functions can be imported into Python scripts for automation or integration into larger assessment workflows.

Connecting to LDAP and Enumerating Templates

from doom.protocols.ldap import get_ldap_connection
from doom.modules.enumerate_templates import enumerate_templates

# Establish an LDAP connection

ldap_conn, base_dn = get_ldap_connection(
    host="10.0.0.5",
    username="analyst",
    password="Secret123!",
    domain="corp.local"
)

# Retrieve all certificate templates

templates = enumerate_templates(ldap_conn, base_dn)

# Display key security properties

for tmpl in templates:
    print(f"Template: {tmpl['display_name']}")
    attrs = tmpl["attributes"]
    print("  Auto-Enrollment:", attrs.get("Auto_Enrollment"))
    print("  Requires Manager Approval:", attrs.get("Requires_Manager_Approval"))

Parsing Raw Attributes Manually

from doom.parsers.attribute import parse_attribute

# Decode a raw enrollment flag value

raw_flags = 0x00000020
readable = parse_attribute("msPKI-Enrollment-Flag", raw_flags)
print(readable)  # Output: "32 (Auto_Enrollment)"

Summary

  • Doom is a Python-based Textual TUI application for auditing AD CS certificate templates.
  • It automates LDAP discovery, template enumeration, and attribute parsing through modular components in src/doom/.
  • The three-screen interface (Login, Loading, Main) provides a guided workflow from authentication to interactive template exploration.
  • Security analysts can use Doom to identify misconfigurations such as weak enrollment flags, missing manager approvals, or overly permissive private-key settings.
  • The tool supports both interactive TUI usage and programmatic integration via its Python API.

Frequently Asked Questions

What is the Doom tool used for?

Doom is a security auditing tool designed to help analysts explore Active Directory Certificate Services (AD CS) certificate templates. It translates complex LDAP data into human-readable attributes, making it easier to spot security misconfigurations like auto-enrollment settings or weak cryptographic policies.

How does Doom connect to Active Directory?

Doom uses an LDAP bind operation implemented in src/doom/protocols/ldap.py to connect to the domain controller. It automatically attempts LDAPS (LDAP over SSL) if plain LDAP fails, then locates the Certificate Templates container in the AD configuration partition to begin enumeration.

Can I use Doom programmatically without the TUI?

Yes, while Doom is primarily a Textual TUI application, you can import its core modules directly. The doom.protocols.ldap and doom.modules.enumerate_templates modules provide functions to establish LDAP connections and retrieve certificate template data for use in custom scripts or automated assessment pipelines.

What types of security misconfigurations can Doom detect?

Doom parses attributes that reveal critical security settings, including auto-enrollment flags that allow users to request certificates without approval, missing manager approval requirements for sensitive templates, and overly permissive private-key settings that might allow key export. By presenting these values in decoded, human-readable format, Doom helps auditors quickly identify templates that violate security best practices.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →