← Back to Feed

The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI

July 7, 2026 · Google Cloud Security · Severity: MEDIUM

Google Cloud Security explores how active ADFS signing keys can be recovered through machine DPAPI, enabling the Golden SAML attack technique first described in 2017. The research highlights that this persistence method remains a significant threat to federated identity environments. Organizations are urged to harden DPAPI protection and monitor for unauthorized key access.

Key Takeaways

  • The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI — Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk...
  • Staying informed on emerging threats is key to maintaining a strong security posture.
  • Regular security awareness training and layered defenses remain the foundation of any effective cybersecurity program.
☕ Buy a Coffee