← Back to Feed
The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI
July 7, 2026 · Google Cloud Security · Severity: HIGH
This article details how manually rotated ADFS certificates can leave active signing keys exposed in Machine DPAPI, creating 'ghost' certificates. Attackers can exploit these to forge SAML tokens without touching LSASS or the live ADFS service. The technique highlights configuration drift that bypasses multifactor authentication and conditional access.
Key Takeaways
- Golden SAML attack exploits ADFS token-signing certificate private keys for authentication bypass.
- Manual certificate rotation with AutoCertificateRollover disabled can expose keys via Machine DPAPI.
- Ghost certificates remain decryptable but unused, enabling stealthy SAML token forgery attacks.