← Back to Feed
The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI
July 7, 2026 · Google Cloud Security · Severity: HIGH
This article details a new attack vector where manually rotated ADFS certificates leave active signing keys exposed in Machine DPAPI, creating 'ghost certificates.' Attackers can extract these certificates to forge high-privilege SAML tokens, bypassing MFA and other controls, while avoiding monitored components like LSASS.
Key Takeaways
- Manual rotation of ADFS certificates can leave active signing keys exposed in Machine DPAPI.
- Attackers can extract ghost certificates to forge SAML tokens and bypass MFA.
- This technique avoids direct interaction with LSASS and live ADFS service processes.