Analytics BIOC
Informational
✕
Unusual access to the Windows Internal Database on an ADFS server
The Windows Internal Database (WID) was queried in an unusual way on an ADFS server.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Credentials from Password Stores (T1555)
Attacker's goals:
Attackers can attempt to extract and decrypt the ADFS certificate that is used to sign SAML tokens, and fabricate a new SAML token.
Investigative actions:
See whether this was a legitimate action. Follow the causality chain/user/host activities. Monitor suspicious LDAP queries to the ADFS container in Active Directory. Check the possibility of a compromised ADFS server. Check for unusual Azure AD authentications. Check for unusual logins.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Suspicious access to the Windows Internal Database on an ADFS server Low (parent: Informational)