Analytics BIOC Informational

Modification of the AD FS IdentityServer configuration file

The AD FS service configuration file was modified.

Module:
Identity Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003) Defense Evasion (TA0005)
ATT&CK techniques: Hijack Execution Flow (T1574)
Detector tags: Active Directory Federation Services Analytics
Attacker's goals:

The attacker's goal is to establish a persistent, high-privilege backdoor by forcing the service to load a malicious configuration that enables remote code execution and the bypass of security controls like MFA.

Investigative actions:

Check if the AD FS service was stopped or restarted around the time of modification. Investigate the process and user that performed the write operation for signs of compromise.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Suspicious Modification of the AD FS IdentityServer configuration file Low (parent: Informational)