Rule Info
Name
ADCS - Certighost Certificate Issued via CDC Chase (CVE-2026-54121)
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects successful issuance of an ADCS certificate where the request attributes include
'cdc' (Client DC) or 'rmd' (Remote Domain) pointing to a non-DC domain or IP, confirming the
CA's chase fallback path was taken against an attacker-controlled target.
'cdc' directs the CA to an address for identity lookup; 'rmd' specifies the principal to
look up there. In an attack (CVE-2026-54121, Certighost), cdc points to a rogue host that
returns a forged DC identity. A successfully issued certificate at this stage means the
attacker has obtained a cert carrying a Domain Controller's SID and DNS identity, enabling
PKINIT authentication as that DC followed by DCSync replication.
Date
2026-07-27 00:00:00
Modified
None
Id
8b7e2c54-1f93-4a6d-b8e0-3c9d7f25a168
Tags
attack.privilege-escalation attack.credential-access attack.t1649 cve.2026-54121 detection.emerging-threats
Type
Community Rule
Link to Public Repo
Rule History
Author
Title
Date
Commit
Swachchhanda Shrawan Poudel
Merge PR #6190 from @swachchhanda000 - Add CertiGhost Rules
2026-08-05
