AD CS ESC8 Certificate Request via NTLM

Detects Active Directory Certificate Services (AD CS) certificate requests that utilize NTLM authentication rather than Kerberos. This behavior is indicative of potential NTLM relay attacks (ESC8), where an attacker forces a machine account to authenticate to the AD CS web enrollment endpoint via NTLM to obtain a certificate on behalf of that machine.