Monitor certificate-based logons

If your environment does not normally use smart cards or certificate-based authentication, or if a user who does not typically authenticate using smart cards suddenly generates events with TokenHasThisOrgCertificateSid, this may warrant investigation, as it could indicate authentication using a fraudulently issued certificate.