For the complete documentation index, see llms.txt. This page is also available as Markdown.

Unusual access to the Windows Internal Database on an ADFS server

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Credentials from Password Stores (T1555)

Severity

Informational

Description

The Windows Internal Database (WID) was queried in an unusual way on an ADFS server.

Attacker's Goals

  • Attackers can attempt to extract and decrypt the ADFS certificate that is used to sign SAML tokens, and fabricate a new SAML token.

Investigative actions

  • See whether this was a legitimate action.

  • Follow the causality chain/user/host activities.

  • Monitor suspicious LDAP queries to the ADFS container in Active Directory.

  • Check the possibility of a compromised ADFS server.

  • Check for unusual Azure AD authentications.

  • Check for unusual logins.

Variations

Suspicious access to the Windows Internal Database on an ADFS server

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Credentials from Password Stores (T1555)

Severity

Low

Description

The Windows Internal Database (WID) was queried in an unusual way on an ADFS server.

Attacker's Goals

  • Attackers can attempt to extract and decrypt the ADFS certificate that is used to sign SAML tokens, and fabricate a new SAML token.

Investigative actions

  • See whether this was a legitimate action.

  • Follow the causality chain/user/host activities.

  • Monitor suspicious LDAP queries to the ADFS container in Active Directory.

  • Check the possibility of a compromised ADFS server.

  • Check for unusual Azure AD authentications.

  • Check for unusual logins.

Was this helpful?