Best Detection of 2026 Series: AD CS ESC1 Certificate SAN Enrollment Followed by Mismatched Kerberos TGT
This rule detects a correlation between an Active Directory Certificate Services (AD CS) certificate request (Event ID 4887) containing certificate attributes (SAN, altname, or UPN) and a subsequent Kerberos TGT request (Event ID 4768) within an hour, where the requested account name does not match the ticket user. This behavior is indicative of potential certificate-based authentication abuse, such as 'ESC1' or 'Golden Certificate' attacks where a certificate is requested and immediately used for credential impersonation.
Cortex XDR

