ADCS Certificate Template Configuration Vulnerability

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Detects certificate creation with template allowing risk permission subject

Severity

Attention

Rule Requirement

Criteria

Action1: actionname = "Certificate Service Operation" AND TEMPLATE contains "CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT" OR NEWTEMPLATE contains "CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT" select Action1.HOSTNAME,Action1.MESSAGE,Action1.NEWTEMPLATE,Action1.TEMPLATE

Detection

Execution Mode

realtime

Log Sources

Active Directory

Author

Orlinum , BlueDefenZer