Windows ADCS Template Enrollment Supplies Subject and Risky EKU (Event ID 4898/4899)
Flags ADCS template load/update events (4898/4899) when risky EKU OIDs and enrollee-supplied subject are present.
- Product
- windows
- Service
- security
- Author
- Orlinum , BlueDefenZer (SigmaHQ), DRL 1.1
- Published
- 2021-11-17
- Updated
- 2026-07-31
What it detects
This rule identifies ADCS certificate template creation or update events (Event ID 4898 and 4899) where the template content includes specific EKU OIDs associated with risky certificate usage and the template flag indicates the enrollees can supply the subject. An attacker can abuse misconfigured templates to obtain certificates with attacker-controlled subject fields, potentially enabling privilege escalation or credential abuse. It relies on Windows Security logs from the Certificate Services event stream containing TemplateContent/NewTemplateContent and the presence of the subject-supply flag and listed EKU OIDs.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows ADCS Template Enrollment Supplies Subject and Risky EKU (Event ID 4898/4899)
id: 2541e5e5-8ee2-46b0-bd07-07afddda2115
status: test
description: This rule identifies ADCS certificate template creation or update events (Event ID 4898 and 4899) where the template content includes specific EKU OIDs associated with risky certificate usage and the template flag indicates the enrollees can supply the subject. An attacker can abuse misconfigured templates to obtain certificates with attacker-controlled subject fields, potentially enabling privilege escalation or credential abuse. It relies on Windows Security logs from the Certificate Services event stream containing TemplateContent/NewTemplateContent and the presence of the subject-supply flag and listed EKU OIDs.
references:
- https://www.specterops.io/assets/resources/Certified_Pre-Owned.pdf
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_adcs_certificate_template_configuration_vulnerability_eku.yml
author: Orlinum , BlueDefenZer, Huntrule Team
date: 2021-11-17
modified: 2022-12-25
tags:
- attack.privilege-escalation
- attack.credential-access
logsource:
product: windows
service: security
definition: Certificate services loaded a template would trigger event ID 4898 and certificate Services template was updated would trigger event ID 4899. A risk permission seems to be coming if template contain specific flag with risky EKU.
detection:
selection10:
EventID: 4898
TemplateContent|contains:
- 1.3.6.1.5.5.7.3.2
- 1.3.6.1.5.2.3.4
- 1.3.6.1.4.1.311.20.2.2
- 2.5.29.37.0
selection11:
TemplateContent|contains: CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT
selection20:
EventID: 4899
NewTemplateContent|contains:
- 1.3.6.1.5.5.7.3.2
- 1.3.6.1.5.2.3.4
- 1.3.6.1.4.1.311.20.2.2
- 2.5.29.37.0
selection21:
NewTemplateContent|contains: CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT
condition: (selection10 and selection11) or (selection20 and selection21)
falsepositives:
- Administrator activity
- Proxy SSL certificate with subject modification
- Smart card enrollement
level: high
license: DRL-1.1
related:
- id: bfbd3291-de87-4b7c-88a2-d6a5deb28668
type: derived