Join our Newsletter — 33% off our NHI Course

What are the signs that an AD CS attack path is being abused?

Look for unusual certificate template requests, SAN or UPN values that do not fit normal enrolment patterns, and tooling associated with privilege escalation attempts. A blocked enrolment can also be a useful signal when policy starts denying requests that previously succeeded. Those patterns show that a template is being used as an access vector.

How an AD CS abuse path usually shows up

An abused AD CS path is rarely silent because certificate enrollment has a shape. The strongest signs are requests that do not fit the normal identity, device, or business context for that template, especially when the request is made to obtain a certificate that can be used for a higher-privilege logon or service impersonation.

Watch for certificate requests that carry unusual subject alternative names, unexpected UPN values, or requester patterns that diverge from the normal population for that template. In practice, that means comparing the request against who normally enrolls, what names they normally receive, and whether the certificate purpose matches the account or workload that submitted it.

A second clue is a change in tooling or operator behaviour. Active Directory and Entra ID Hardening Guide is relevant here because AD CS abuse often appears alongside privilege-escalation tradecraft, delegation abuse, and other abnormal identity movement that shows up as a new path to access rather than a normal certificate lifecycle event.

What request and policy anomalies matter most

Template abuse tends to stand out in the details. Look for enrollment requests that suddenly succeed for an identity that never used that template before, requests issued from an atypical host, or certificate contents that indicate the requester is trying to bind a more powerful identity than the environment would normally allow. Those are the kinds of changes that turn a certificate service into an access path.

Policy denials can also be valuable signals, especially when they begin after a period of success. A blocked enrollment may mean the request has crossed into a template, subject name, or issuance path that defenders have started to restrict. That is important because it can reveal an attacker probing for a path that still works elsewhere, even if one request is stopped.

Template misconfiguration is often the enabling condition, so a good comparison point is whether the request violates the template’s intended enrollment population, subject handling, or issuance constraints. Identity Security Posture Management (ISPM) Guide supports that line of analysis because posture findings often expose configuration drift, standing privilege, and access paths that look legitimate until they are tested against actual policy.

Which signals should trigger immediate investigation

The most actionable signal set is a cluster, not a single event. Unusual certificate requests, abnormal SAN or UPN values, and tooling associated with escalation attempts become much more meaningful when they occur together, or when they are followed by authentication activity that does not match the requester’s usual behavior.

Also look for repeated attempts across multiple templates, since that can indicate enumeration or trial-and-error against issuance rules. An attacker often does not know which template will succeed, so the pattern may be broad first and precise later. The State of NHI & AI Agent Breach Report 2026 is useful background for the broader pattern of identity misuse because it shows how stolen or misused access material is commonly converted into lateral movement and privilege gain.

If the certificate request is immediately useful for authentication, impersonation, or delegation, treat it as a high-priority incident signal rather than a routine PKI event. The operational question is not just whether the request was allowed, but whether the issued material could be used to cross a trust boundary that defenders assumed was protected.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack surface, NIST SP 800-53 Rev 5 sets the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
MITRE ATT&CK T1649 — Steal or Forge Authentication Certificates AD CS abuse centers on certificate-based authentication misuse.
Recommendation — Map suspicious certificate issuance to certificate-forgery tradecraft and hunt for abuse across authentication paths.
NIST SP 800-53 Rev 5 AU-6 — Audit Review, Analysis, and Reporting Suspicious certificate enrollment needs log review and anomaly analysis.
Recommendation — Review CA and enrollment logs for abnormal SAN, UPN, and requester patterns.
ISO/IEC 27001:2022 A.8.15 — Logging AD CS abuse detection depends on retaining and monitoring certificate service logs.
Recommendation — Ensure certificate service events are logged and monitored for abnormal enrollment behavior.

Practitioner Guidance

What to verify: compare each suspicious request against the normal requester population, template purpose, and expected SAN or UPN format. If the certificate content would not be acceptable for a standard enrollment workflow, it deserves manual review before any trust decision is made.

What to prioritise: focus first on templates that can influence authentication or privileged access, then on requests that were denied after prior success. That combination usually provides the clearest line between benign enrollment noise and a path being actively tested for abuse.

Common mistake: teams often review only issuance success and miss the denied attempts, which are frequently the best indicator that policy is starting to catch an abuse pattern. Another common miss is treating a certificate request as harmless because it looks like normal PKI traffic, even when the subject details are clearly abnormal.

Practitioner takeaway: the most useful AD CS abuse signal is deviation from the normal enrollment shape, especially when abnormal request content and privilege-oriented tooling appear together. Investigate the request path, not just the issued certificate, because the path itself often reveals the attack before the certificate is widely used.