← Back to Feed

The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI

July 7, 2026 · Google Cloud Security · Severity: HIGH

Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem.

Key Takeaways

  • Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017.
  • By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user to any.
  • Technical Insight: Encountering the ‘Ghost Certificate’ Analysts followed the standard DKM extraction path.
☕ Buy a Coffee