Unusual access to the Windows Internal Database on an ADFS server
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Credentials from Password Stores (T1555)
Severity
Informational
Description
The Windows Internal Database (WID) was queried in an unusual way on an ADFS server.
Attacker's Goals
Attackers can attempt to extract and decrypt the ADFS certificate that is used to sign SAML tokens, and fabricate a new SAML token.
Investigative actions
See whether this was a legitimate action.
Follow the causality chain/user/host activities.
Monitor suspicious LDAP queries to the ADFS container in Active Directory.
Check the possibility of a compromised ADFS server.
Check for unusual Azure AD authentications.
Check for unusual logins.
Variations
Was this helpful?
