Potential CertiGhost AD CS Machine Identity Mismatch (CVE-2026-54121)
Identifies successful Active Directory Certificate Services (AD CS) certificate issuance events where a machine-account requester differs from the Remote Machine Discovery (RMD) chase target while the event's DNS subject alternative name (SAN) matches that target. This requester-to-target mismatch may indicate CertiGhost (CVE-2026-54121) or similar abuse of AD CS request-context chase processing.
Elastic rule (View on GitHub)
1[metadata]
2creation_date = "2026/08/12"
3integration = ["system"]
4maturity = "production"
5updated_date = "2026/09/18"
6
7[rule]
8author = ["Elastic"]
9description = """
10Identifies successful Active Directory Certificate Services (AD CS) certificate issuance events where a machine-account
11requester differs from the Remote Machine Discovery (RMD) chase target while the event's DNS subject alternative name
12(SAN) matches that target. This requester-to-target mismatch may indicate CertiGhost (CVE-2026-54121) or similar abuse
13of AD CS request-context chase processing.
14"""
15from = "now-9m"
16language = "esql"
17license = "Elastic License v2"
18name = "Potential CertiGhost AD CS Machine Identity Mismatch (CVE-2026-54121)"
19references = [
20 "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54121",
21 "https://gist.github.com/H0j3n/a5ef2609b5f2944ac2390a191a534c26",
22 "https://github.com/aniqfakhrul/CVE-2026-54121",
23]
24risk_score = 73
25rule_id = "2985ea6e-5b1e-4845-9a57-95f7f78b35f1"
26severity = "high"
27tags = [
28 "Domain: Endpoint",
29 "Domain: Identity",
30 "OS: Windows",
31 "Use Case: Threat Detection",
32 "Tactic: Credential Access",
33 "Tactic: Privilege Escalation",
34 "Use Case: Active Directory Monitoring",
35 "Use Case: Vulnerability",
36 "Data Source: Active Directory",
37 "Data Source: Windows Security Event Logs",
38 "Resources: Investigation Guide",
39 "Noise: Unknown",
40 "Performance: Normal",
41 "Profile: Recommended",
42 "Threat: Vulnerability Exploit",
43 "Rule Type: ES|QL",
44 "Platform: Windows",
45 "Vuln: CVE-2026-54121",
46]
47timestamp_override = "event.ingested"
48type = "esql"
49
50query = '''
51FROM logs-system.security-* METADATA _id, _index, _version
52| WHERE event.code == "4887" AND
53 winlog.event_data.Requester LIKE "*$" AND
54 winlog.event_data.Attributes IS NOT NULL
55
56// Parse Attributes for RMD and CDC, and as a fallback when dedicated template or SAN fields are absent.
57// CDC and the effective template are retained for triage purposes
58| GROK winlog.event_data.Attributes
59 """(?im)^[ \t]*CertificateTemplate[ \t]*:[ \t]*(?<Esql.attributes_certificate_template>[^\r\n]+)\r?$"""
60| GROK winlog.event_data.Attributes
61 """(?im)^[ \t]*SAN[ \t]*:[ \t]*dns[ \t]*=[ \t]*(?<Esql.attributes_san_value>[^\r\n]+)\r?$"""
62| GROK winlog.event_data.SubjectAlternativeName
63 """(?im)^[ \t]*DNS[ \t]+Name[ \t]*=[ \t]*(?<Esql.event_san_value>[^\r\n]+)\r?$"""
64| GROK winlog.event_data.Attributes
65 """(?im)^[ \t]*cdc[ \t]*:[ \t]*(?<Esql.cdc_value>[^\r\n]+)\r?$"""
66| GROK winlog.event_data.Attributes
67 """(?im)^[ \t]*rmd[ \t]*:[ \t]*(?<Esql.rmd_value>[^\r\n]+)\r?$"""
68| EVAL Esql.effective_certificate_template = TRIM(COALESCE(
69 winlog.event_data.CertificateTemplate,
70 Esql.attributes_certificate_template
71 )),
72 Esql.san_value = TRIM(COALESCE(Esql.event_san_value, Esql.attributes_san_value)),
73 Esql.cdc_value = TRIM(Esql.cdc_value),
74 Esql.rmd_value = TRIM(Esql.rmd_value),
75 Esql.normalized_requester = TO_LOWER(
76 REPLACE(winlog.event_data.Requester, """^.*\\|\$$""", "")
77 ),
78 Esql.normalized_san_value = TO_LOWER(
79 REPLACE(Esql.san_value, """\.$""", "")
80 ),
81 Esql.normalized_rmd_value = TO_LOWER(
82 REPLACE(Esql.rmd_value, """\.$""", "")
83 )
84// Preserve IP-shaped values; shorten other SAN and RMD values to the first DNS label for machine-account comparison.
85| EVAL Esql.san_is_ip_shaped =
86 Esql.normalized_san_value RLIKE """[0-9]{1,3}(\.[0-9]{1,3}){3}""" OR Esql.normalized_san_value LIKE "*:*",
87 Esql.rmd_is_ip_shaped =
88 Esql.normalized_rmd_value RLIKE """[0-9]{1,3}(\.[0-9]{1,3}){3}""" OR Esql.normalized_rmd_value LIKE "*:*"
89| EVAL Esql.normalized_san_target = CASE(
90 Esql.san_is_ip_shaped,
91 Esql.normalized_san_value,
92 REPLACE(Esql.normalized_san_value, """\..*$""", "")
93 ),
94 Esql.normalized_rmd_target = CASE(
95 Esql.rmd_is_ip_shaped,
96 Esql.normalized_rmd_value,
97 REPLACE(Esql.normalized_rmd_value, """\..*$""", "")
98 )
99| WHERE Esql.normalized_requester IS NOT NULL AND
100 Esql.normalized_san_target IS NOT NULL AND
101 Esql.normalized_rmd_target IS NOT NULL
102| WHERE Esql.normalized_requester != Esql.normalized_rmd_target AND
103 Esql.normalized_san_target == Esql.normalized_rmd_target
104| KEEP @timestamp, _id, _index, _version, event.code, event.action, event.category, event.type, event.outcome,
105 event.created, event.ingested, data_stream.dataset, data_stream.namespace, host.id, host.name,
106 winlog.computer_name, winlog.record_id, winlog.event_data.RequestId, winlog.event_data.Requester,
107 winlog.event_data.CertificateTemplate, winlog.event_data.Subject, winlog.event_data.SubjectAlternativeName,
108 winlog.event_data.Attributes, winlog.event_data.Disposition, winlog.event_data.SubjectKeyIdentifier,
109 Esql.effective_certificate_template, Esql.san_value, Esql.cdc_value, Esql.rmd_value,
110 Esql.normalized_requester, Esql.normalized_san_target, Esql.normalized_rmd_target
111'''
112
113setup = """## Setup
114
115Audit Certification Services must be enabled on enterprise certification authorities so that successful certificate
116issuance generates Security event 4887.
117
118The Windows Security integration must retain `winlog.event_data.Attributes`, including the requested SAN and chase
119attributes. The rule prefers dedicated certificate-template and subject-alternative-name fields when present and uses
120`Attributes` as a fallback. Dropped, truncated, or rewritten attributes create a visibility gap and do not indicate
121benign activity.
122
123Setup instructions: https://ela.st/audit-certification-services
124"""
125
126note = """## Triage and analysis
127
128### Investigating Potential CertiGhost AD CS Machine Identity Mismatch (CVE-2026-54121)
129
130#### Possible investigation steps
131
132- Does the matched AD CS issuance record validate the identity mismatch?
133 - Focus: `event.code`, `winlog.event_data.RequestId`, `winlog.event_data.Requester`, `Esql.san_value`, `Esql.rmd_value`
134 - Hint: Reopen the Windows Security 4887 record on the same CA host and request ID. Compare the parsed SAN and RMD with the complete `winlog.event_data.Attributes` and dedicated SAN field; additional SAN values or disagreement keep the case unresolved. $investigate_0
135 - Implication: Event 4887 proves successful issuance, and the alert establishes that the requester differs from the RMD target while the parsed SAN matches that target. This is an operational anti-pattern. Close as benign only when CA records and test records identify an authorized CertiGhost or AD CS security test matching the exact CA, request ID, requester, target, template, and time.
136- What identity and authentication capability did the issued certificate receive?
137 - Focus: `Esql.effective_certificate_template`, `winlog.event_data.Subject`, `winlog.event_data.SubjectAlternativeName`, `winlog.event_data.SubjectKeyIdentifier`
138 - Hint: Retrieve the issued certificate and CA request/template configuration for the same request ID. Inspect the certificate's actual subject, SAN, EKUs or application policies, validity and revocation state, and the template's subject-name settings and enrollment permissions.
139 - Implication: Event 4887 and the template name alone do not establish the complete certificate contents or authentication capability. A certificate that represents the RMD target and permits authentication increases the likelihood and impact of credential abuse. Missing certificate or template configuration is unresolved, not benign.
140- What other issuances by the requester appear on the same CA host?
141 - Focus: `host.id`, `winlog.event_data.Requester`, `winlog.event_data.RequestId`, `winlog.event_data.Attributes`, `winlog.event_data.SubjectAlternativeName`
142 - Hint: Recover 4887 events for the same requester on this CA host. $investigate_1
143 - Implication: Repeated successful requests for different SAN/RMD targets expand the potential abuse scope. One isolated request does not reduce the significance of the current mismatch.
144- What other CA events reference the same target identity?
145 - Focus: `Esql.san_value`, `Esql.rmd_value`, `winlog.event_data.Attributes`, `winlog.event_data.SubjectAlternativeName`, `winlog.event_data.Requester`
146 - Hint: Copy the alert's exact SAN and RMD values into a scoped Timeline or Discover search for raw 4886, 4887, and 4888 records on the same CA host. Use contains or wildcard matching against `winlog.event_data.Attributes` and `winlog.event_data.SubjectAlternativeName`; derived `Esql.*` fields exist only on the alert.
147 - Implication: Requests for the same target from additional unexpected accounts expand the affected scope. The absence of other matching events does not clear the current issuance.
148- Did the CA connect to the CDC value during certificate processing?
149 - Focus: `host.id`, `Esql.cdc_value`, `destination.ip`, `destination.port`, `process.name`
150 - Hint: When the CDC value is an IP address, search network events from the CA host around issuance for that `destination.ip`. For a hostname, resolve it from collected DNS or asset evidence before comparing destination IPs. Review LDAP or LDAPS from `certsrv.exe` and SMB from `System` without requiring either process for all callback traffic.
151 - Implication: CA-host LDAP or SMB traffic to the CDC value supports request-context chase activity, but neither the CDC attribute nor a connection alone proves exploitation. Missing DNS or CA network telemetry is unresolved, not benign.
152- Does surrounding activity show requester creation or target-certificate use?
153 - Focus: `event.code`, `winlog.event_data.Requester`, `Esql.normalized_rmd_target`, `winlog.event_data.TargetUserName`, `winlog.event_data.PreAuthType`
154 - Hint: After validating the issuance, inspect account-management events where `winlog.event_data.TargetUserName` matches the requester account name without its domain prefix. Inspect successful 4768 events with `winlog.event_data.PreAuthType` equal to `16`. For DNS-shaped RMD values, compare `winlog.event_data.TargetUserName` with the normalized RMD target plus `$`; for IP-shaped values, first resolve the associated computer account from AD, asset, or CA evidence. Treat later authentication as corroboration unless identity and certificate evidence establish the relationship.
155 - Implication: Requester creation or change followed by target PKINIT strengthens the exploitation hypothesis. Missing account-management or domain-controller authentication telemetry is unresolved, not benign.
156
157Escalate when the mismatch is not an authorized test, the issued certificate can authenticate as the target, or callback and follow-on evidence corroborate abuse. Close only when CA, certificate, and test records establish the exact authorized scope; preserve and escalate when evidence or visibility is mixed or incomplete.
158
159### False positive analysis
160
161The detected requester-to-target relationship is an operational anti-pattern and did not appear in the self-aligned enrollment controls. Authorized CertiGhost or AD CS security testing is the only currently validated benign explanation. Treat other claimed cross-identity enrollment workflows as unresolved until the 4887 source event, CA request record, issued certificate, template configuration, requester, target, CA, and time scope align without contradictions.
162
163Do not close on recurrence, absence of related alerts, or the requester account name alone. ES|QL fields created by the query cannot be used in rule exceptions. If an exception is required for recurring authorized testing, combine narrowly scoped source fields such as the CA `host.id`, `winlog.event_data.Requester`, and the exact `winlog.event_data.Attributes` pattern. Avoid exceptions based only on a host, requester, or template.
164
165### Response and remediation
166
167- Preserve the 4887 source record, CA request and database records, issued certificate and identifiers, template configuration, and relevant authentication and network evidence before disruptive action.
168- Identify affected certification authorities and apply the Microsoft security update or mitigation for CVE-2026-54121. Review request history for the requester and target to identify additional certificates requiring action.
169- If malicious activity is confirmed, revoke the affected certificate and verify that revocation information is distributed. Disable or remove an attacker-controlled requester account after preserving evidence. Rotate the target machine credentials and invalidate affected authentication material when certificate use or impersonation is established.
170- Isolate an endpoint only when host evidence attributes compromise to that system. The requester account may not map to a managed endpoint, and the target identity alone does not prove that the target endpoint was compromised.
171- Record confirmed certificate identifiers, affected principals, CA configuration gaps, and telemetry gaps for the responsible response, PKI, identity, and detection owners.
172"""
173[rule.investigation_fields]
174field_names = [
175 "@timestamp",
176 "event.code",
177 "host.id",
178 "host.name",
179 "winlog.computer_name",
180 "winlog.record_id",
181 "winlog.event_data.RequestId",
182 "winlog.event_data.Requester",
183 "winlog.event_data.CertificateTemplate",
184 "winlog.event_data.Subject",
185 "winlog.event_data.SubjectAlternativeName",
186 "winlog.event_data.Attributes",
187 "winlog.event_data.Disposition",
188 "winlog.event_data.SubjectKeyIdentifier",
189 "Esql.effective_certificate_template",
190 "Esql.san_value",
191 "Esql.rmd_value",
192 "Esql.cdc_value",
193 "Esql.normalized_requester",
194 "Esql.normalized_san_target",
195 "Esql.normalized_rmd_target",
196]
197
198[[transform.investigate]]
199label = "Matched certificate issuance"
200description = "Finds the Windows Security 4887 certificate issuance record on the same CA host and request ID."
201providers = [[
202 { excluded = false, field = "event.code", queryType = "phrase", value = "4887", valueType = "string" },
203 { excluded = false, field = "host.id", queryType = "phrase", value = "{{host.id}}", valueType = "string" },
204 { excluded = false, field = "winlog.event_data.RequestId", queryType = "phrase", value = "{{winlog.event_data.RequestId}}", valueType = "string" },
205]]
206relativeFrom = "now-24h"
207relativeTo = "now"
208
209[[transform.investigate]]
210label = "Same requester issuances"
211description = "Finds successful certificate issuance events for the same requester on the same CA host."
212providers = [[
213 { excluded = false, field = "event.code", queryType = "phrase", value = "4887", valueType = "string" },
214 { excluded = false, field = "host.id", queryType = "phrase", value = "{{host.id}}", valueType = "string" },
215 { excluded = false, field = "winlog.event_data.Requester", queryType = "phrase", value = "{{winlog.event_data.Requester}}", valueType = "string" },
216]]
217relativeFrom = "now-7d"
218relativeTo = "now"
219
220
221[[rule.threat]]
222framework = "MITRE ATT&CK"
223[[rule.threat.technique]]
224id = "T1649"
225name = "Steal or Forge Authentication Certificates"
226reference = "https://attack.mitre.org/techniques/T1649/"
227
228[[rule.threat.technique]]
229id = "T1212"
230name = "Exploitation for Credential Access"
231reference = "https://attack.mitre.org/techniques/T1212/"
232
233
234[rule.threat.tactic]
235id = "TA0006"
236name = "Credential Access"
237reference = "https://attack.mitre.org/tactics/TA0006/"
238[[rule.threat]]
239framework = "MITRE ATT&CK"
240[[rule.threat.technique]]
241id = "T1068"
242name = "Exploitation for Privilege Escalation"
243reference = "https://attack.mitre.org/techniques/T1068/"
244
245
246[rule.threat.tactic]
247id = "TA0004"
248name = "Privilege Escalation"
249reference = "https://attack.mitre.org/tactics/TA0004/"
Triage and analysis
Investigating Potential CertiGhost AD CS Machine Identity Mismatch (CVE-2026-54121)
Possible investigation steps
- Does the matched AD CS issuance record validate the identity mismatch?
- Focus:
event.code,winlog.event_data.RequestId,winlog.event_data.Requester,Esql.san_value,Esql.rmd_value - Hint: Reopen the Windows Security 4887 record on the same CA host and request ID. Compare the parsed SAN and RMD with the complete
winlog.event_data.Attributesand dedicated SAN field; additional SAN values or disagreement keep the case unresolved. $investigate_0 - Implication: Event 4887 proves successful issuance, and the alert establishes that the requester differs from the RMD target while the parsed SAN matches that target. This is an operational anti-pattern. Close as benign only when CA records and test records identify an authorized CertiGhost or AD CS security test matching the exact CA, request ID, requester, target, template, and time.
- Focus:
- What identity and authentication capability did the issued certificate receive?
- Focus:
Esql.effective_certificate_template,winlog.event_data.Subject,winlog.event_data.SubjectAlternativeName,winlog.event_data.SubjectKeyIdentifier - Hint: Retrieve the issued certificate and CA request/template configuration for the same request ID. Inspect the certificate's actual subject, SAN, EKUs or application policies, validity and revocation state, and the template's subject-name settings and enrollment permissions.
- Implication: Event 4887 and the template name alone do not establish the complete certificate contents or authentication capability. A certificate that represents the RMD target and permits authentication increases the likelihood and impact of credential abuse. Missing certificate or template configuration is unresolved, not benign.
- Focus:
- What other issuances by the requester appear on the same CA host?
- Focus:
host.id,winlog.event_data.Requester,winlog.event_data.RequestId,winlog.event_data.Attributes,winlog.event_data.SubjectAlternativeName - Hint: Recover 4887 events for the same requester on this CA host. $investigate_1
- Implication: Repeated successful requests for different SAN/RMD targets expand the potential abuse scope. One isolated request does not reduce the significance of the current mismatch.
- Focus:
- What other CA events reference the same target identity?
- Focus:
Esql.san_value,Esql.rmd_value,winlog.event_data.Attributes,winlog.event_data.SubjectAlternativeName,winlog.event_data.Requester - Hint: Copy the alert's exact SAN and RMD values into a scoped Timeline or Discover search for raw 4886, 4887, and 4888 records on the same CA host. Use contains or wildcard matching against
winlog.event_data.Attributesandwinlog.event_data.SubjectAlternativeName; derivedEsql.*fields exist only on the alert. - Implication: Requests for the same target from additional unexpected accounts expand the affected scope. The absence of other matching events does not clear the current issuance.
- Focus:
- Did the CA connect to the CDC value during certificate processing?
- Focus:
host.id,Esql.cdc_value,destination.ip,destination.port,process.name - Hint: When the CDC value is an IP address, search network events from the CA host around issuance for that
destination.ip. For a hostname, resolve it from collected DNS or asset evidence before comparing destination IPs. Review LDAP or LDAPS fromcertsrv.exeand SMB fromSystemwithout requiring either process for all callback traffic. - Implication: CA-host LDAP or SMB traffic to the CDC value supports request-context chase activity, but neither the CDC attribute nor a connection alone proves exploitation. Missing DNS or CA network telemetry is unresolved, not benign.
- Focus:
- Does surrounding activity show requester creation or target-certificate use?
- Focus:
event.code,winlog.event_data.Requester,Esql.normalized_rmd_target,winlog.event_data.TargetUserName,winlog.event_data.PreAuthType - Hint: After validating the issuance, inspect account-management events where
winlog.event_data.TargetUserNamematches the requester account name without its domain prefix. Inspect successful 4768 events withwinlog.event_data.PreAuthTypeequal to16. For DNS-shaped RMD values, comparewinlog.event_data.TargetUserNamewith the normalized RMD target plus$; for IP-shaped values, first resolve the associated computer account from AD, asset, or CA evidence. Treat later authentication as corroboration unless identity and certificate evidence establish the relationship. - Implication: Requester creation or change followed by target PKINIT strengthens the exploitation hypothesis. Missing account-management or domain-controller authentication telemetry is unresolved, not benign.
- Focus:
Escalate when the mismatch is not an authorized test, the issued certificate can authenticate as the target, or callback and follow-on evidence corroborate abuse. Close only when CA, certificate, and test records establish the exact authorized scope; preserve and escalate when evidence or visibility is mixed or incomplete.
False positive analysis
The detected requester-to-target relationship is an operational anti-pattern and did not appear in the self-aligned enrollment controls. Authorized CertiGhost or AD CS security testing is the only currently validated benign explanation. Treat other claimed cross-identity enrollment workflows as unresolved until the 4887 source event, CA request record, issued certificate, template configuration, requester, target, CA, and time scope align without contradictions.
Do not close on recurrence, absence of related alerts, or the requester account name alone. ES|QL fields created by the query cannot be used in rule exceptions. If an exception is required for recurring authorized testing, combine narrowly scoped source fields such as the CA host.id, winlog.event_data.Requester, and the exact winlog.event_data.Attributes pattern. Avoid exceptions based only on a host, requester, or template.
Response and remediation
- Preserve the 4887 source record, CA request and database records, issued certificate and identifiers, template configuration, and relevant authentication and network evidence before disruptive action.
- Identify affected certification authorities and apply the Microsoft security update or mitigation for CVE-2026-54121. Review request history for the requester and target to identify additional certificates requiring action.
- If malicious activity is confirmed, revoke the affected certificate and verify that revocation information is distributed. Disable or remove an attacker-controlled requester account after preserving evidence. Rotate the target machine credentials and invalidate affected authentication material when certificate use or impersonation is established.
- Isolate an endpoint only when host evidence attributes compromise to that system. The requester account may not map to a managed endpoint, and the target identity alone does not prove that the target endpoint was compromised.
- Record confirmed certificate identifiers, affected principals, CA configuration gaps, and telemetry gaps for the responsible response, PKI, identity, and detection owners.
References
Related rules
- Potential Privileged Escalation via SamAccountName Spoofing
- Remote Computer Account DnsHostName Update
- PKINIT Followed by Same-Principal U2U Service Ticket
- Potential Kerberos Relay Attack against a Computer Account
- Access to a Sensitive LDAP Attribute