ADCS Abuse via certreq.exe or certutil.exe (ESC1/ESC8 - T1649)

Detects potential abuse of Active Directory Certificate Services (AD CS) by monitoring for suspicious command-line activity from 'certreq.exe' and 'certutil.exe' associated with certificate enrollment, submission, or management. It also identifies the staging of certificate-related files (.pem, .pfx, .p12, .crt, .cer, .key) in common user directories.