Rule Info
Name
ADCS - Certighost Ghost Machine Account Creation
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the creation of a machine account whose name starts with 'GHOST', which is the
naming convention used by the CVE-2026-54121 (Certighost) exploit tooling.
The public proof-of-concept for Certighost creates a temporary machine account with a
name of the form GHOST<random>$ before enrolling for a DC certificate via the cdc chase
path. The attacker-controlled machine account is used as the requester identity in the
certificate request; the cdc attribute then redirects the CA to a rogue host that returns
a forged Domain Controller identity. The resulting certificate carries the DC's SID and
DNS name, enabling full PKINIT authentication as the targeted DC followed by DCSync.
A machine account creation event (4741) where TargetUserName starts with 'GHOST' and
ends with '$' is a high-fidelity indicator of this attack tool's execution. Legitimate
environments very rarely provision machine accounts with this prefix.
Date
2026-07-30 00:00:00
Modified
None
Id
fa0bac5f-d170-4a91-9780-1ad71dc1f49e
Tags
attack.privilege-escalation attack.credential-access attack.persistence attack.t1136.002 attack.t1649 cve.2026-54121 detection.emerging-threats
Type
Community Rule
Link to Public Repo
Rule History
Author
Title
Date
Commit
Swachchhanda Shrawan Poudel
Merge PR #6190 from @swachchhanda000 - Add CertiGhost Rules
2026-08-05
