drop ad cs ca audit log · detect esc1-esc11 template abuse patterns
flags ESC1–ESC11 template misconfigurations · correlates issued certs with vulnerable templates · web enrollment abuse bursts
heuristic screener · template flag parsing varies by export tool — indicative ESC mapping only · not definitive proof