CertiGhost CVE-2026-54121: Non-DC account issued DC identity certificate

This rule monitors for successful certificate enrollments (Event ID 4886 and 4887) using sensitive certificate templates typically reserved for domain controllers or Kerberos authentication. It specifically alerts when these requests are made by user accounts that do not end in '$' (machine accounts) and are not known service accounts like 'CAService', which may indicate unauthorized attempts to obtain high-privilege credentials via AD Certificate Services (AD CS).