Microsoft AD CS audit
About 2,040 selected Security records per day from one synthetic certification authority, with reconstructed version 0 XML.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/identity-microsoft-adcs/generator.yml \
--id adcs \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| 4886 | Request received | 50% | iam |
| 4887 | Certificate issued | 49% | iam |
| 4888 | Short-key denial | 1% | iam |
| 4885 | Audit filter changed or restored | Less than 1% | configuration |
Realism Features
- Request and disposition share request ID, requester, process and thread
- Ordinary and episode audit reductions end after 15–32 minutes
- The selected records do not prove certificate contents or authentication capability
Sample Output
{
"@timestamp": "2026-09-20T00:01:00+00:00",
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "certificate-issued",
"category": [
"iam"
],
"code": "4887",
"kind": "event",
"original": "\u003cEvent xmlns=\"http://schemas.microsoft.com/win/2004/08/events/event\"\u003e\u003cSystem\u003e\u003cProvider Name=\"Microsoft-Windows-Security-Auditing\" Guid=\"{54849625-5478-4994-A5BA-3E3B0328C30D}\"/\u003e\u003cEventID\u003e4887\u003c/EventID\u003e\u003cVersion\u003e0\u003c/Version\u003e\u003cLevel\u003e0\u003c/Level\u003e\u003cTask\u003e12805\u003c/Task\u003e\u003cOpcode\u003e0\u003c/Opcode\u003e\u003cKeywords\u003e0x8020000000000000\u003c/Keywords\u003e\u003cTimeCreated SystemTime=\"2026-09-20T00:01:00.000000Z\"/\u003e\u003cEventRecordID\u003e310040\u003c/EventRecordID\u003e\u003cCorrelation/\u003e\u003cExecution ProcessID=\"652\" ThreadID=\"724\"/\u003e\u003cChannel\u003eSecurity\u003c/Channel\u003e\u003cComputer\u003eca01.corp.example\u003c/Computer\u003e\u003cSecurity/\u003e\u003c/System\u003e\u003cEventData\u003e\u003cData Name=\"RequestId\"\u003e3001\u003c/Data\u003e\u003cData Name=\"Requester\"\u003eCORP\\device28$\u003c/Data\u003e\u003cData Name=\"Attributes\"\u003eCertificateTemplate:CorpUserCN\u003c/Data\u003e\u003cData Name=\"Disposition\"\u003e3\u003c/Data\u003e\u003cData Name=\"SubjectKeyIdentifier\"\u003ed2 e2 10 0e 83 83 55 37 58 e3 26 db 96 e0 24 df e6 03 58 26\u003c/Data\u003e\u003cData Name=\"Subject\"\u003eCN=device28$\u003c/Data\u003e\u003c/EventData\u003e\u003c/Event\u003e",
"outcome": "success",
"provider": "Microsoft-Windows-Security-Auditing",
"type": [
"creation"
]
},
"host": {
"name": "ca01.corp.example"
},
"observer": {
"name": "CORP-CA",
"type": "certificate-authority"
},
"related": {
"user": [
"device28$"
]
},
"user": {
"domain": "CORP",
"name": "device28$"
},
"winlog": {
"channel": "Security",
"computer_name": "ca01.corp.example",
"event_data": {
"Attributes": "CertificateTemplate:CorpUserCN",
"Disposition": "3",
"RequestId": "3001",
"Requester": "CORP\\device28$",
"Subject": "CN=device28$",
"SubjectKeyIdentifier": "d2 e2 10 0e 83 83 55 37 58 e3 26 db 96 e0 24 df e6 03 58 26"
},
"event_id": "4887",
"keywords": [
"Audit Success"
],
"level": "information",
"opcode": "Info",
"process": {
"pid": 652,
"thread": {
"id": 724
}
},
"provider_guid": "{54849625-5478-4994-A5BA-3E3B0328C30D}",
"provider_name": "Microsoft-Windows-Security-Auditing",
"record_id": "310040",
"task": "Certification Services",
"time_created": "2026-09-20T00:01:00.000000Z"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Include recurring correlations |
| anomaly_interval_hours | 24 | Recurrence hours, minimum 6 |
| ca_host | ca01.corp.example | CA server hostname |
| domain | CORP | Account domain |
| ca_name | CORP-CA | Configured CA name, collector context |
| suspicious_requester | svc-enroll | First administrator, shared by ordinary work and episodes |
| privileged_upn | administrator@corp.example | Requested UPN shared by both modes |
| routine_template | CorpUserCN | Fictional CN-from-AD enrollment template |
| enrollment_template | CorpUserSuppliedSAN | Fictional supplied-subject enrollment template |
Related Generators
Keycloak 26.7.4 Event Log
Keycloak 26.7.4 jboss-logging user and admin event lines for one realm with 1,500 users and 5 administrators, as native text in event.original with keycloak.*, user.*, source.* and url.* fields following the Elastic keycloak.log pipeline. Recurring episodes show one administrator failing five to eight logins from a VPN egress address, then logging in to the admin console and granting a privileged realm role.
Active Directory audit
About 21,800 normalized Security records per day from a small domain, with Kerberos, NTLM and temporary group membership.
ALD Pro domain controller
About 61,200 selected records/day from one domain controller, including native KDC, LDAP access and audit records.