BeyondTrust Identity Security Insights Active Directory Certificate Services abuse detected

This rule is part of a beta feature. To learn more, contact Support.
beyondtrust-identity-security-insights

Classification:

attack

Goal

Detect activity with potentially suspicious or unauthorized certificates that may indicate certificate misuse.

Strategy

Monitor certificate activity to identify unexpected usage patterns, or deviations from approved certificates.

Triage and Response

  1. Identify the account {{@entityName}} associated with the certificate request and review the context of the activity.
  2. Review the information associated with the alert to understand the nature and potential impact of the activity.
  3. Validate whether the certificate request aligns with approved roles, responsibilities, and operational requirements.
  4. If the activity is unauthorized, take appropriate remediation actions in accordance with organizational incident response procedures.