#GoldenSAML
⚡ Identity is the new perimeter.

Attackers no longer need to breach the network.
They just log into Okta or Entra ID.

Golden SAML • AiTM (Evilginx3) • OAuth Illicit Consent

Full technical analysis + hardening & detection (SPL + KQL):

#IdPAttacks #Okta #EntraID #GoldenSAML #CyberSecurity
September 10, 2026 at 3:20 PM
@mandiant.com
ADFS token-signing keys stored in Machine DPAPI can be recovered by SYSTEM-level processes without touching LSASS, enabling Golden SAML attacks that bypass MFA.
-
IOCs: (None identified)
-
#ADFS #DPAPI #GoldenSAML #ThreatIntel
Recovering Active ADFS Signing Keys via Machine DPAPI
cloud.google.com
July 7, 2026 at 8:17 PM
Mandiant found a "ghost" ADFS certificate entry can expose the active signing key via Machine DPAPI when AutoCertificateRollover is off, enabling forged SAML assertions, MFA bypass, and access to Microsoft 365 and Entra ID. #ADFS #GoldenSAML #EntraID
The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI
Mandiant showed that in ADFS environments with AutoCertificateRollover disabled and manual certificate rotation, a “ghost” certificate entry can leave the active token-signing key recoverable from Machine DPAPI. If that key is obtained, attackers can forge SAML assertions to impersonate users, bypass MFA, and gain access to federated services such as Microsoft 365 and Entra ID. #ADFS #EntraID #Microsoft365 #GoldenSAML
www.hendryadrian.com
July 7, 2026 at 6:45 PM
They didn't break in. They were the update. 🕵️‍♂️💻 We expose the #SolarWinds hack: how Russian spies used #GoldenSAML to bypass MFA & infiltrate the Pentagon. Was the password really "solarwinds123"? The perfect supply chain attack. #TechTakedown.

🎧 LISTEN NOW 👇
open.spotify.com/episode/2xlr...
Spotify – Web Player
open.spotify.com
December 7, 2025 at 2:40 PM