0

How does one defend, detect and deter golden SAML attacks?

نور
  • 111
  • 6
Nathan Aw
  • 1
  • 7
  • 12
  • Related: https://security.stackexchange.com/questions/242146/solarwinds-orion-saml-compromise-mass-cert-update – explunit Jan 21 '21 at 15:44

1 Answers1

1

Several methods could be used to detect'em:

  1. Correlating service provider login events with corresponding authentication events in ADFS and Domain Controllers

  2. Identifying certificate export events in Active Directory Federation Services

  3. Customizing SAML response to identify irregular access

  4. Detecting malicious Ative Directory Federation Services trust modification

Those methods are well documented here

And for mitigation, the best you could do is following best practice guides and recommendations, Microsoft provides an excellent resource for doing this.

FireEye published a well-detailed paper on the attack and provides some extra guidance on ADFS attack mitigation: Remediation and Hardening Strategies for Microsoft 365 to Defend Against UNC2452

If not using ADFS this should help.

Andrew K.
  • 304
  • 1
  • 7
Soufiane Tahiri
  • 2,667
  • 12
  • 27