Detecting Certighost (CVE-2026-54121): Sigma Coverage Across the Full Attack Chain
ID: 430d2f84-41bd-57ee-bc55-1b4b1f7b6cc2
STIX ID: report--430d2f84-41bd-57ee-bc55-1b4b1f7b6cc2
Feed Name: Nextron Systems
Certighost (CVE-2026-54121) is a high-impact AD CS vulnerability where a CA configured with the EDITF_ENABLECHASECLIENTDC flag will follow an attacker-supplied 'cdc' address, accept a forged Domain Controller identity, and issue a DC certificate; an attacker can then obtain a DC TGT via PKINIT and perform DCSync to extract all domain credentials including krbtgt. The report reproduces the attack in-lab, provides detailed evidence (CA/DC/network logs), supplies seven Sigma detection rules and supporting checks, and recommends either disabling the chase flag or applying the July 2026 patch that validates chase targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
