Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1555 ✕
Download CSV Show ATT&CK heatmapUnusual access to the Windows Internal Database on an ADFS server Informational 1 variation
The Windows Internal Database (WID) was queried in an unusual way on an ADFS server.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Credentials from Password Stores (T1555)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Attackers can attempt to extract and decrypt the ADFS certificate that is used to sign SAML tokens, and fabricate a new SAML token.Investigative actions: See whether this was a legitimate action. Follow the causality chain/user/host activities. Monitor suspicious LDAP queries to the ADFS container in Active Directory. Check the possibility of a compromised ADFS server. Check for unusual Azure AD authentications. Check for unusual logins.Variations
Suspicious access to the Windows Internal Database on an ADFS server
Low overridden
The Windows Internal Database (WID) was queried in an unusual way on an ADFS server. overridden