ADCS - Certighost Ghost Machine Account Creation

Rule Info

Name
ADCS - Certighost Ghost Machine Account Creation
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the creation of a machine account whose name starts with 'GHOST', which is the naming convention used by the CVE-2026-54121 (Certighost) exploit tooling. The public proof-of-concept for Certighost creates a temporary machine account with a name of the form GHOST<random>$ before enrolling for a DC certificate via the cdc chase path. The attacker-controlled machine account is used as the requester identity in the certificate request; the cdc attribute then redirects the CA to a rogue host that returns a forged Domain Controller identity. The resulting certificate carries the DC's SID and DNS name, enabling full PKINIT authentication as the targeted DC followed by DCSync. A machine account creation event (4741) where TargetUserName starts with 'GHOST' and ends with '$' is a high-fidelity indicator of this attack tool's execution. Legitimate environments very rarely provision machine accounts with this prefix.
Date
2026-07-30 00:00:00
Modified
None
Id
fa0bac5f-d170-4a91-9780-1ad71dc1f49e
Tags
attack.privilege-escalation attack.credential-access attack.persistence attack.t1136.002 attack.t1649 cve.2026-54121 detection.emerging-threats
Type
Community Rule

Rule History

Author
Title
Date
Commit
Swachchhanda Shrawan Poudel
Merge PR #6190 from @swachchhanda000 - Add CertiGhost Rules
2026-08-05