Module 7 Links and Resources GOLDEN SAML ADFS Saml Blog: https://blog.sygnia.co/detection-and-hunting-of-golden-saml-attack Export DKM Commands: https://simulandlabs.com/labs/GoldenSAML/simulation/export-adfs-dkm-key/exportADFSDKMKeyLDAP.html ADFS Configuration (AADINTERNALS) https://aadinternals.com/post/adfs/ Export ADFS Configuration: https://simulandlabs.com/labs/GoldenSAML/simulation/export-adfs-configuration/exportADFSConfigLocalNamedPipe.html Export Token Signing Certificate: https://simulandlabs.com/labs/GoldenSAML/simulation/export-adfs-certificates/exportADFSCertsDKMKey.html Forge SAML Token: https://simulandlabs.com/labs/GoldenSAML/simulation/sign-new-samltoken/README.html HTTP Request (Netwrix) https://www.netwrix.com/golden_saml_attack.html Mandiant ADFSDUMP https://github.com/mandiant/ADFSDump SACL to Detect DKM Export: https://simulandlabs.com/labs/GoldenSAML/simulation/export-adfs-dkm-key/exportADFSDKMKeyLDAP.html Enable ADFS Logging: https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/enabling-ad-fs-security-auditing-and-shipping-event-logs-to/ba-p/3610464 Revoke Refresh Tokens: https://learn.microsoft.com/en-us/powershell/module/azuread/revoke-azureaduserallrefreshtoken?view=azureadps-2.0 ________________ ATTACKING KEY VAULTS List Keys and Secrets Secrets: https://.vault.azure.net/secrets/ Keys: https://.vault.azure.net/keys/ KQL AzureDiagnostics| where ResourceProvider=="MICROSOFT.KEYVAULT"| summarize count() by CallerIPAddress, OperationName, requestUri_s ________________ SKELETON KEY Adam Chester Blog: https://blog.xpnsec.com/azuread-connect-for-redteam/ PTASpy: https://github.com/Gerenios/public/blob/master/PTASpy.cpp ________________ STEALING ACCESS TOKENS FROM OFFICE APPS @MrD0X Writeup: https://mrd0x.com/stealing-tokens-from-office-applications/ JWT Decode: https://jwt.io/ MSFT Token Tactics Writeup: https://www.microsoft.com/en-us/security/blog/2022/11/16/token-tactics-how-to-prevent-detect-and-respond-to-cloud-token-theft/