Skip to content
The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI Mandiant Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obtaining the pri...
The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI | Huntaegis