Detection rules › By eventMicrosoft-Windows-Security-Auditing event 48862 detection rules reference this event. View event page.Splunk (2)Windows Steal Authentication Certificates - ESC1 Abuse T1649 Windows Steal Authentication Certificates Certificate Request T1649