← Back to feed
Threat Actors & CampaignsEmerging1 sourceJul 7, 2026 · 14:00via Mandiant / Google TI

The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI

Brief

Written by: Shebin Mathew

Introduction

The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021 , remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem.

By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user to any SAML-federated application, bypassing multifactor authentication (MFA), conditional access, and all identity-based controls.

However, during a recent red team engagement, Mandiant discovered that when ADFS certificates are manually rotated, configuration drift can silently leave active signing keys exposed in Machine DPAPI.

Read more on Mandiant / Google TI