For the complete documentation index, see llms.txt. This page is also available as Markdown.

Privileged certificate request via certificate template

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)

Detection Modules

Identity Analytics

Detector Tags

Active Directory Certificate Services Analytics

ATT&CK Tactic

Privilege Escalation (TA0004)

ATT&CK Technique

Valid Accounts: Domain Accounts (T1078.002)

Severity

Informational

Description

A privileged certificate was requested via certificate template.

Attacker's Goals

An attacker may attempt to exploit the Active Directory Certificate Services to escalate privileges to a domain controller or privileged account.

Investigative actions

  • Check if this is a legitimate certificate request.

  • Check if the certificate issued was used to request a Kerberos ticket.

  • Investigate actions done with the issued certificate and its owner.

  • Check for possible NTLM relay alerts.

Variations

Suspicious privileged certificate request denied via certificate template

Synopsis

Field
Value

ATT&CK Tactic

Privilege Escalation (TA0004)

ATT&CK Technique

Valid Accounts: Domain Accounts (T1078.002)

Severity

Medium

Description

A suspicious privileged certificate request was denied via certificate template.

Attacker's Goals

An attacker may attempt to exploit the Active Directory Certificate Services to escalate privileges to a domain controller or privileged account.

Investigative actions

  • Check if this is a legitimate certificate request.

  • Check if the certificate issued was used to request a Kerberos ticket.

  • Investigate actions done with the issued certificate and its owner.

  • Check for possible NTLM relay alerts.

Suspicious privileged certificate request via certificate template

Synopsis

Field
Value

ATT&CK Tactic

Privilege Escalation (TA0004)

ATT&CK Technique

Valid Accounts: Domain Accounts (T1078.002)

Severity

Low

Description

A suspicious privileged certificate was requested via certificate template.

Attacker's Goals

An attacker may attempt to exploit the Active Directory Certificate Services to escalate privileges to a domain controller or privileged account.

Investigative actions

  • Check if this is a legitimate certificate request.

  • Check if the certificate issued was used to request a Kerberos ticket.

  • Investigate actions done with the issued certificate and its owner.

  • Check for possible NTLM relay alerts.

Was this helpful?