Masquerading Certificate Issuance with Certighost cdc and rmd Request Attributes (via security)

PremiumReviewedSigma · High · v1
Product
windows
Service
security
Author
HuntRule
Published
2026-05-10
Updated
2026-08-28

ATT&CK techniques

Persistence → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects certificate issuance events carrying the cdc or rmd request attributes used by the Certighost CVE-2026-54121 exploit to steer a Certificate Authority toward an attacker-chosen client Domain Controller. Adversaries leverage these attributes to obtain a certificate that authenticates as a Domain Controller machine account, making early detection critical for exposing certificate-based DC impersonation before DCSync.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.