Modification of the AD FS IdentityServer configuration file
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Analytics
Detector Tags
Active Directory Federation Services Analytics
ATT&CK Tactic
Stealth (TA0005)
ATT&CK Technique
Hijack Execution Flow (T1574)
Severity
Informational
Description
The AD FS service configuration file was modified.
Attacker's Goals
The attacker's goal is to establish a persistent, high-privilege backdoor by forcing the service to load a malicious configuration that enables remote code execution and the bypass of security controls like MFA.
Investigative actions
Check if the AD FS service was stopped or restarted around the time of modification.
Investigate the process and user that performed the write operation for signs of compromise.
Variations
Was this helpful?
