AD CS Certificate Abuse - ESC Attack for Privilege Escalation via Forged Certificate
This rule monitors Active Directory Certificate Services (AD CS) event logs for signs of potential privilege escalation and credential abuse. It specifically targets indicators of ESC1 (AD CS misconfigurations allowing requester-supplied SANs), identifies requests for certificates by non-owners for privileged accounts, and monitors for the use of PKI-based Kerberos authentication against high-privilege targets.
Microsoft Sentinel (KQL)

