Detection rules › By eventMicrosoft-Windows-Security-Auditing event 48873 detection rules reference this event. View event page.Splunk (3)Windows Steal Authentication Certificates - ESC1 Abuse T1649 Windows Steal Authentication Certificates - ESC1 Authentication T1550, T1649 Windows Steal Authentication Certificates Certificate Issued T1649