AD CS Golden Certificate: CA Key Theft & Anomalous Cert Issuance
Detects potential Certificate Authority (CA) key theft by correlating command-line execution of certutil (with export flags) on a CA server with subsequent suspicious certificate issuance events. Suspicious issuance includes unauthorized certificate requests (missing event 4886), requests for high-privilege subjects (e.g., Domain Admins), or requests with unusually long validity periods.
Microsoft Sentinel (KQL)

