PKINIT Certificate Authentication via Weak Certificate related to Shadow Credentials & AD CS abuse
Detects successful Kerberos PKINIT authentication (Event 4768, PreAuthType 16) issued by on-premises certificate authorities. This activity is a potential indicator of Shadow Credentials or Active Directory Certificate Services (AD CS) abuse where attackers use forged or stolen certificates to authenticate as domain users or machines.
Cortex XDR

