← Back to Feed

The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI

July 7, 2026 · Google Cloud Security · Severity: HIGH

This article details a new attack vector where manually rotated ADFS certificates leave active signing keys exposed in Machine DPAPI, creating 'ghost certificates.' Attackers can extract these certificates to forge high-privilege SAML tokens, bypassing MFA and other controls, while avoiding monitored components like LSASS.

Key Takeaways

  • Manual rotation of ADFS certificates can leave active signing keys exposed in Machine DPAPI.
  • Attackers can extract ghost certificates to forge SAML tokens and bypass MFA.
  • This technique avoids direct interaction with LSASS and live ADFS service processes.
☕ Buy a Coffee