Golden SAML: AD FS federation abuse & token-signing cert access
This rule monitors for ADFS-related security events that may indicate credential theft or authentication bypass attempts. It flags anomalous federated sign-in events (e.g., MFA bypass, unfamiliar location), unauthorized access to the ADFS DKM container in Active Directory, and suspicious attempts to export ADFS token-signing certificates.
Microsoft Sentinel (KQL)

