2026 Critical Cloud Identity Detection: SAML Token-Signing Certificate Export or Rollover
Detects high-risk activities related to SAML token-signing certificates, including certificate export from Active Directory Federation Services (AD FS) or Active Directory Certificate Services (AD CS) and unauthorized configuration changes to enterprise application certificate management. These activities are potential precursors to Golden SAML attacks, where an adversary attempts to forge authentication tokens.
YARA-L

