For the complete documentation index, see llms.txt. This page is also available as Markdown.

Modification of the AD FS IdentityServer configuration file

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

Detection Modules

Identity Analytics

Detector Tags

Active Directory Federation Services Analytics

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Hijack Execution Flow (T1574)

Severity

Informational

Description

The AD FS service configuration file was modified.

Attacker's Goals

The attacker's goal is to establish a persistent, high-privilege backdoor by forcing the service to load a malicious configuration that enables remote code execution and the bypass of security controls like MFA.

Investigative actions

  • Check if the AD FS service was stopped or restarted around the time of modification.

  • Investigate the process and user that performed the write operation for signs of compromise.

Variations

Suspicious Modification of the AD FS IdentityServer configuration file

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Hijack Execution Flow (T1574)

Severity

Low

Description

The AD FS service configuration file was modified.

Attacker's Goals

The attacker's goal is to establish a persistent, high-privilege backdoor by forcing the service to load a malicious configuration that enables remote code execution and the bypass of security controls like MFA.

Investigative actions

  • Check if the AD FS service was stopped or restarted around the time of modification.

  • Investigate the process and user that performed the write operation for signs of compromise.

Was this helpful?