Active Directory Shadow Credentials: Abusing msDS-KeyCredentialLink for AD Persistence and Privilege Escalation Abuse msDS-KeyCredentialLink to forge Key Trust certificates, authenticate via PKINIT, and recover NTLM hashes. 2026.05.08 Active Directory