AD CS Abuse via certreq.exe or certutil.exe Unusual Enrollment

This rule detects potential Active Directory Certificate Services (AD CS) abuse (specifically ESC1 and ESC8 patterns) by monitoring command-line executions of 'certreq.exe' and 'certutil.exe' that utilize suspicious flags or originate from non-standard administrative processes. This activity is indicative of an attacker attempting to enroll certificates for unauthorized entities or escalate privileges within a Windows domain.