NTLM Relay to AD CS Web Enrollment (certfnsh.asp) via NTLM Auth

Detects potential NTLM relay attacks targeting Active Directory Certificate Services (AD CS) web enrollment endpoints, including subsequent certificate requests for sensitive templates. This pattern identifies attackers attempting to relay NTLM authentication to AD CS and potentially requesting certificates for high-privilege templates (e.g., DomainController, SubCA, Machine, or User) to facilitate privilege escalation.