Golden SAML: ADFS Cert Theft via Mimikatz, AdfsConfiguration.mdf Access, or AADInternals
Detects techniques associated with Golden SAML attacks, including the use of Mimikatz for ADFS token-signing certificate extraction, the execution of AADInternals PowerShell cmdlets for SAML token forgery, and unauthorized access to the ADFS configuration database (AdfsConfiguration.mdf).
SentinelOne

