ADCS Certificate Template Configuration Vulnerability with Risky EKU
Description
Detects certificate creation with template allowing risk permission subject and risky EKU
Query · sigma
selection10: EventID: 4898 TemplateContent|contains: - 1.3.6.1.5.5.7.3.2 - 1.3.6.1.5.2.3.4 - 1.3.6.1.4.1.311.20.2.2 - 2.5.29.37.0 selection11: TemplateContent|contains: CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT selection20: EventID: 4899 NewTemplateContent|contains: - 1.3.6.1.5.5.7.3.2 - 1.3.6.1.5.2.3.4 - 1.3.6.1.4.1.311.20.2.2 - 2.5.29.37.0 selection21: NewTemplateContent|contains: CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT condition: (selection10 and selection11) or (selection20 and selection21)
Known false positives
- Administrator activity
- Proxy SSL certificate with subject modification
- Smart card enrollement