ADFS DKM Key Access
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Threat Module
Detector Tags
Active Directory Federation Services Analytics
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Forge Web Credentials: SAML Tokens (T1606.002)
Severity
Low
Description
ADFS DKM key attribute (thumbnailphoto) access in AD container, potential Golden SAML token forging attempt.
Attacker's Goals
The attack goal is to forge a valid SAML token to impersonate any user and gain persistent, unauthorized access to cloud resources, effectively bypassing MFA and standard security controls.
Investigative actions
Check for recent changes to the SAML signing certificate on both the Identity Provider and the Service Provider to rule out a configuration drift or expiration issue.
Check for other correlated alerts on on-premises systems that may be related to the Golden SAML attack.
Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).
Was this helpful?
