Windows AD CS Certificate Template Updated/Created Enrollee Supplies Subject Flag
Alerts when AD CS certificate templates are created or updated with CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT.
- Product
- windows
- Service
- security
- Author
- Orlinum , BlueDefenZer (SigmaHQ), DRL 1.1
- Published
- 2021-11-17
- Updated
- 2026-07-31
What it detects
This rule flags Active Directory Certificate Services activity where a certificate template contains the CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT setting, observed during template creation (event 4898) or template updates (event 4899). Attackers can leverage this template behavior to influence certificate subject enrollment outcomes, which can support privilege escalation or credential access paths. It relies on Windows Security logs from certificate services events containing TemplateContent/NewTemplateContent fields with the specified flag.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows AD CS Certificate Template Updated/Created Enrollee Supplies Subject Flag
id: 627656d9-9f88-4c30-b36c-08f8c124852a
status: test
description: This rule flags Active Directory Certificate Services activity where a certificate template contains the CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT setting, observed during template creation (event 4898) or template updates (event 4899). Attackers can leverage this template behavior to influence certificate subject enrollment outcomes, which can support privilege escalation or credential access paths. It relies on Windows Security logs from certificate services events containing TemplateContent/NewTemplateContent fields with the specified flag.
references:
- https://www.specterops.io/assets/resources/Certified_Pre-Owned.pdf
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_adcs_certificate_template_configuration_vulnerability.yml
author: Orlinum , BlueDefenZer, Huntrule Team
date: 2021-11-17
modified: 2022-12-25
tags:
- attack.privilege-escalation
- attack.credential-access
logsource:
product: windows
service: security
definition: Certificate services loaded a template would trigger event ID 4898 and certificate Services template was updated would trigger event ID 4899. A risk permission seems to be coming if template contain specific flag.
detection:
selection1:
EventID: 4898
TemplateContent|contains: CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT
selection2:
EventID: 4899
NewTemplateContent|contains: CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT
condition: selection1 or selection2
falsepositives:
- Administrator activity
- Proxy SSL certificate with subject modification
- Smart card enrollement
level: low
license: DRL-1.1
related:
- id: 5ee3a654-372f-11ec-8d3d-0242ac130003
type: derived