Event ID 4887: Certificate issued
- Event ID
- 4887
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Active Directory
- Default logging
- Needs configuration
What event 4887 means
Event 4887 is written by an AD CS certification authority when it issues a certificate, either automatically under the template and CA policy or after a certificate manager approves a pending request. It repeats the RequestId, Requester and Attributes of the 4886 request and adds the Disposition, the SubjectKeyIdentifier and the certificate Subject.
This is the record that a credential was actually minted. The key question is whether the identity in the certificate matches the account that asked for it: a regular user obtaining a certificate whose subject is an administrator or a domain controller points to template or CA misconfiguration abuse.
Certificates stay valid until they expire or are revoked, even after the account's password changes, so an issued certificate for a privileged identity is also a persistence mechanism.
When it is logged
Advanced Audit Policy Configuration > Object Access > Audit Certification Services (Success), plus "Issue and manage certificate requests" enabled on the Auditing tab of the CA properties (the CA audit filter).
Logged only on the CA server. Older builds do not include the subject alternative name requested in the CSR, so a certificate issued with a privileged SAN may show an unremarkable Subject; check the certificate in the CA database.
Key fields
| Field | What it tells you |
|---|---|
| RequestId | CA request number; joins with 4886 and with the CA database record. |
| Requester | Account that submitted the request. |
| Attributes | Request attributes supplied with the request (e.g. ccm: client machine name, or san: where accepted). |
| Disposition | Request disposition code from the CA; for an issued certificate this is the issued status (3). |
| SubjectKeyIdentifier | Subject key identifier of the issued certificate — useful to find the same certificate elsewhere. |
| Subject | Distinguished name of the certificate subject, e.g. CN=Administrator, CN=Users, DC=contoso, DC=local. |
Common benign sources
- Autoenrollment issuing user, computer and domain controller certificates.
- Renewals of web server and service certificates by their owners.
- Certificate managers approving pending requests after review.
What attackers do that produces it
- Issuance of a certificate for a privileged account to a low-privileged requester through a vulnerable template, followed by PKINIT authentication as that account.
- Certificates issued for machine or DC identities to accounts that are not those machines.
- Burst of issuances from rarely used templates by a single requester.
Investigation tips
- Compare
RequesterwithSubjectand with the SAN recorded in the CA database; flag privileged identities. - Identify the template used and review its enrollment rights and subject settings.
- Hunt 4768 on domain controllers for certificate-based (PKINIT) TGT requests for the same identity.
- If abuse is confirmed, revoke the certificate by serial number; a password reset alone does not invalidate it.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1649 Steal or Forge Authentication Certificates | Credential Access |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.