For the complete documentation index, see llms.txt. This page is also available as Markdown.

ADFS DKM Key Access

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)

Detection Modules

Identity Threat Module

Detector Tags

Active Directory Federation Services Analytics

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Forge Web Credentials: SAML Tokens (T1606.002)

Severity

Low

Description

ADFS DKM key attribute (thumbnailphoto) access in AD container, potential Golden SAML token forging attempt.

Attacker's Goals

The attack goal is to forge a valid SAML token to impersonate any user and gain persistent, unauthorized access to cloud resources, effectively bypassing MFA and standard security controls.

Investigative actions

  • Check for recent changes to the SAML signing certificate on both the Identity Provider and the Service Provider to rule out a configuration drift or expiration issue.

  • Check for other correlated alerts on on-premises systems that may be related to the Golden SAML attack.

  • Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).

Was this helpful?