AD CS ESC4 Certificate Template Object Modification
Detects unauthorized modifications to Active Directory Certificate Services (AD CS) template objects (pKICertificateTemplate) using Windows Event ID 5136. This behavior is indicative of ESC4-style attacks, where an adversary with write access to a certificate template modifies security descriptors, enrollment rights, or sensitive configuration flags (like enabling enrollee-supplied SANs or adding a Client Authentication EKU) to facilitate privilege escalation or persistence.
Cortex XDR

