Analytics BIOC
Informational
✕
Modification of the AD FS IdentityServer configuration file
The AD FS service configuration file was modified.
- Module:
- Identity Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003) Defense Evasion (TA0005)
ATT&CK techniques: Hijack Execution Flow (T1574)
Detector tags: Active Directory Federation Services Analytics
Attacker's goals:
The attacker's goal is to establish a persistent, high-privilege backdoor by forcing the service to load a malicious configuration that enables remote code execution and the bypass of security controls like MFA.
Investigative actions:
Check if the AD FS service was stopped or restarted around the time of modification. Investigate the process and user that performed the write operation for signs of compromise.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Suspicious Modification of the AD FS IdentityServer configuration file Low (parent: Informational)