Synopsis
Activation Period |
14 Days |
Training Period |
30 Days |
Test Period |
N/A (single event) |
Deduplication Period |
1 Day |
Required Data |
|
Detection Modules |
Identity Analytics |
Detector Tags |
Active Directory Certificate Services Analytics |
ATT&CK Tactic |
|
ATT&CK Technique |
|
Severity |
Informational |
Description
A possible misconfigured certificate template was loaded by Certificate Services. This may indicate potential certificate template abuse.
Attacker's Goals
An attacker is attempting to exploit AD CS misconfigurations to obtain certificates that can be used for credential theft and privilege escalation.
Investigative actions
- Review the AD CS configuration for vulnerable templates and EKU settings.
- Review AD CS logs to identify any unauthorized certificate issuances, modifications, or template changes.
- Look for signs of certificate template enumeration via LDAP.
- Inspect certificates issued to privileged accounts.
- Check for abnormal PKINIT authentication or elevated Kerberos tickets.
Variations
First detection of AD CS ESC vulnerability in certificate templateCertificate template vulnerable to AD CS ESC attack