---
title: >-
  BeyondTrust Identity Security Insights Active Directory Certificate Services
  abuse detected
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > BeyondTrust Identity Security Insights
  Active Directory Certificate Services abuse detected
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# BeyondTrust Identity Security Insights Active Directory Certificate Services abuse detected

{% alert level="danger" %}
This rule is part of a beta feature. To learn more, [contact Support](https://docs.datadoghq.com/help/).
{% /alert %}
Classification:attack 
## Goal{% #goal %}

Detect activity with potentially suspicious or unauthorized certificates that may indicate certificate misuse.

## Strategy{% #strategy %}

Monitor certificate activity to identify unexpected usage patterns, or deviations from approved certificates.

## Triage and Response{% #triage-and-response %}

1. Identify the account `{{@entityName}}` associated with the certificate request and review the context of the activity.
1. Review the information associated with the alert to understand the nature and potential impact of the activity.
1. Validate whether the certificate request aligns with approved roles, responsibilities, and operational requirements.
1. If the activity is unauthorized, take appropriate remediation actions in accordance with organizational incident response procedures.
