Windows ADCS Template Enrollment Supplies Subject and Risky EKU (Event ID 4898/4899)

Flags ADCS template load/update events (4898/4899) when risky EKU OIDs and enrollee-supplied subject are present.

FreeReviewedSigma · High · v2
Product
windows
Service
security
Author
Orlinum , BlueDefenZer (SigmaHQ), DRL 1.1
Published
2021-11-17
Updated
2026-07-31

What it detects

This rule identifies ADCS certificate template creation or update events (Event ID 4898 and 4899) where the template content includes specific EKU OIDs associated with risky certificate usage and the template flag indicates the enrollees can supply the subject. An attacker can abuse misconfigured templates to obtain certificates with attacker-controlled subject fields, potentially enabling privilege escalation or credential abuse. It relies on Windows Security logs from the Certificate Services event stream containing TemplateContent/NewTemplateContent and the presence of the subject-supply flag and listed EKU OIDs.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.