2026-07-09NOTABLEMandiant recovers a live ADFS signing key from Machine DPAPI, a Golden SAML variant that sidesteps the WID/DKM path and LSASS-watching detection
'Ghost in the Database' ADFS key recovery
tool · tool:adfs-machine-dpapi-key-recovery
Mandiant-documented Golden SAML variant recovering an active ADFS token-signing private key from the machine-scoped Windows CAPI key store via Machine DPAPI when the WID configuration database has drifted from the actively-used signing certificate (AutoCertificateRollover disabled, manual rotation), enables SAML forgery without WID/DKM extraction or LSASS interaction (Mandiant, 2026-07-07).
Aliases: Ghost in the Database
Coverage
1
first 2026-07-09 → last 2026-07-09
Latest activity
2026-07-09
Mandiant recovers a live ADFS signing key from Machine DPAPI, a Golden SAML variant that sidesteps the…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, finance, energy · regions: europe, switzerland
Sources cited
4
3 hosts
Action items (3)
Do-now tasks recorded on the entries about 'Ghost in the Database' ADFS key recovery, newest first. Check the date before acting on an older one.
- Inventory ADFS: run Get-AdfsProperties for AutoCertificateRollover:False and Get-AdfsCertificate to confirm the WID record matches the active token-signing certificate; any Event ID 385 is a drift indicator to investigate.2026-07-09Mandiant recovers a live ADFS signing key from…
- Migrate ADFS token-signing certificates to an HSM (removes the Machine DPAPI extraction path entirely), run ADFS under gMSA, and govern ADFS hosts as Tier 0 with PAWs; when rotating manually, always run Set-AdfsCertificate, not certificate install alone.2026-07-09Mandiant recovers a live ADFS signing key from…
- Deploy SACLs (Event ID 4663) on C:\\ProgramData\\Microsoft\\Crypto\\RSA\\MachineKeys\\ and C:\\Windows\\System32\\Microsoft\\Protect\\S-1-5-18\\, and correlate Entra ID federated sign-ins against ADFS issuance events (299 / 1200-series) to find tokens with no matching upstream authentication.2026-07-09Mandiant recovers a live ADFS signing key from…
Defender insights
What each entry about 'Ghost in the Database' ADFS key recovery tells a defender to do, newest first.
Detection
Story timeline
ATT&CK techniques (3 across 5 tactics)
3 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessValid Accounts: Cloud Accounts
- PersistenceValid Accounts: Cloud Accounts
- Privilege EscalationValid Accounts: Cloud Accounts
- StealthValid Accounts: Cloud Accounts
- Credential AccessUnsecured Credentials · Forge Web Credentials: SAML Tokens
Initial Access TA0001
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery · ATT&CK page ↗
Persistence TA0003
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery · ATT&CK page ↗
Privilege Escalation TA0004
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery · ATT&CK page ↗
Stealth TA0005
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery · ATT&CK page ↗
Credential Access TA0006
T1552Unsecured Credentials×1
Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).
Evidence: 2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery · ATT&CK page ↗
T1606.002Forge Web Credentials: SAML Tokens×1
An adversary may forge SAML tokens with any permissions claims and lifetimes if they possess a valid SAML token-signing certificate. The default lifetime of a SAML token is one hour, but the validity period can be specified in the <code>NotOnOrAfter</code> value of the <code>conditions ...</code> element in a token. This value can be changed using the <code>AccessTokenLifetime</code> in a <code>LifetimeTokenPolicy</code>. Forged SAML tokens enable adversaries to authenticate across services that use SAML 2.0 as an SSO (single sign-on) mechanism.
Evidence: 2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery · ATT&CK page ↗
Entries about 'Ghost in the Database' ADFS key recovery (1)
Where this entity is cited
Source distribution
- cloud.google.com2 (50%)
- cyberark.com1 (25%)
- itbrief.co.uk1 (25%)
All cited sources (4)
- cloud.google.comMandianthttps://cloud.google.com/blog/topics/threat-intelligence/abusing-replication-stealing-adfs-secrets-over-the-network
- cloud.google.comMandiant (Google Cloud Blog / GTIG)https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi
- cyberark.comCyberArk, 2017https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps
- itbrief.co.ukitbrief.co.ukhttps://itbrief.co.uk/story/mandiant-finds-way-to-recover-active-adfs-signing-keys