← Back to Feed
The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI
July 7, 2026 · Google Cloud Security · Severity: HIGH
Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem.
Key Takeaways
- Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017.
- By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user to any.
- Technical Insight: Encountering the ‘Ghost Certificate’ Analysts followed the standard DKM extraction path.