ADCS ESC1 SAN Abuse via Certificate Enrollment - Event 4886
Detects Active Directory Certificate Services (ADCS) certificate enrollment requests where the requester attempts to enroll a certificate with a Subject Alternative Name (SAN) identifying a different principal than the requester's own account. This pattern is indicative of the ESC1 ADCS misconfiguration abuse, which can lead to privilege escalation by impersonating other domain entities.
SentinelOne

