Analytics BIOC Informational

Unusual access to the Windows Internal Database on an ADFS server

The Windows Internal Database (WID) was queried in an unusual way on an ADFS server.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Credentials from Password Stores (T1555)
Attacker's goals:

Attackers can attempt to extract and decrypt the ADFS certificate that is used to sign SAML tokens, and fabricate a new SAML token.

Investigative actions:

See whether this was a legitimate action. Follow the causality chain/user/host activities. Monitor suspicious LDAP queries to the ADFS container in Active Directory. Check the possibility of a compromised ADFS server. Check for unusual Azure AD authentications. Check for unusual logins.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Suspicious access to the Windows Internal Database on an ADFS server Low (parent: Informational)