Shadow Credentials Addition and Subsequent PKINIT Authentication

Detects the addition of a 'msDS-KeyCredentialLink' attribute to an Active Directory object (Event 5136), which is indicative of the Shadow Credentials attack vector, followed by a successful PKINIT authentication (Event 4768) for that account. This combination suggests that an adversary has successfully established persistent access using a forged or unauthorized device credential and is now utilizing it for authentication.