AD CS ESC1: Certificate Request with Enrollee-Supplied SAN + Client Auth EKU

Detects Active Directory Certificate Services (AD CS) certificate requests that include a Subject Alternative Name (SAN) or custom altname attribute, specifically those enabling client authentication. This pattern is commonly associated with the ESC1 privilege escalation technique, where an adversary requests a certificate that impersonates another user or machine account.