Most Popular Detection 2026: AD CS ESC1 Enrollment with Attacker-Supplied SAN

Detects Active Directory Certificate Services (AD CS) enrollment events (4886/4887) where a request includes an enrollee-supplied Subject Alternative Name (SAN). This behavior is characteristic of ESC1 certificate template abuse (e.g., using tools like Certipy or Certify) to request certificates that impersonate other users or machine accounts.