Golden SAML, Second Generation: The Identity Forgery Your EDR Can't See
This variant matters not because it forges a Global Admin — classic Golden SAML did that — but because of where it reads the keys. Prior tradecraft required extracting signing material from the live ADFS configuration or scraping process memory, both of wh
What to do
Classify every remaining ADFS host as Tier 0 this week: enable SACL auditing on MachineKeys/Protect\S-1-5-18, wire Event ID 385 into your SIEM, and migrate signing keys to an HSM.
Add ADFS retirement to this quarter's identity roadmap, moving surviving federations to native Entra ID.