Tag
high
advisory
Windows AD CS ESC1 Certificate Authentication Abuse
2 rules 2 TTPsThis analytic detects the issuance of a suspicious certificate with a Subject Alternative Name (SAN) using Active Directory Certificate Services (AD CS) and its immediate use for authentication, indicating potential exploitation of improperly configured certificate templates for privilege escalation.
Active Directory Certificate Services +3
adcs
certificate_abuse
privilege_escalation
windows
2r
2t
critical
advisory
Kerberos Authentication Relay via DNS CNAME Abuse (CVE-2026-20929)
2 rules 1 TTP 1 CVEAn attacker exploits CVE-2026-20929 by manipulating DNS responses to redirect Kerberos authentication to attacker-controlled AD CS, enabling certificate enrollment for persistent access.
kerberos
relay
adcs
cve-2026-20929
credential-access
2r
1t
1c