ADFSDump is a tool used in post-exploitation against Active Directory Federation Services (AD FS) environments to extract certificates needed for Golden SAML abuse. The provided content specifically identifies it as one of several tools that can help an adversary extract the token-signing material required to forge SAML assertions, alongside certutil.exe, PowerShell, and Mimikatz. It is noted that ADFSDump must be executed under the user context of the AD FS service account. In the described attack chain, theft of the AD FS token-signing certificate/private key enables Golden SAML operations, allowing adversaries to forge SAML responses, impersonate arbitrary users, escalate privileges, and bypass MFA because the legitimate identity provider is removed from the authentication flow. The content ties this broader technique to high-profile activity such as the SolarWinds Orion compromise, but does not directly attribute ADFSDump itself to a specific threat actor. The relevant target environment is Windows infrastructure using AD FS for federated SSO. Detection guidance in the supporting content focuses on certificate export and related activity in AD FS environments, including ADFS Admin events 1200, 1202, 307, and 510; certificate export event 1007; Security event 4688 with command-line logging; PowerShell events 4103 and 4104; Domain Controller event 4769; and Sysmon event 18 for named pipe activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Извлечение закрытого ключа из Windows Internal Database (WID) или SQL Server, где ADFS хранит конфигурацию (T1552.004, Unsecured Credentials: Private Keys). Инструмент: ADFSDump для экспорта конфигурации и ключей
Компрометация ADFS-сервера - privilege escalation до Domain Admin или локального администратора на ADFS-хосте (T1556.007, Modify Authentication Process: Hybrid Identity)
The way that AD FS stores its configuration encryption key involves the use of a Distributed Key Manager (DKM) container which is located in the DC... To summarize the LDAP Object query... thumbnailPhoto attribute is AD FS’ DKM LDAP query example to retrieve the AD FS DKM
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Post-compromise tool referenced for dumping AD FS configuration data; contrasted with FoggyWeb’s in-process access.
Post-exploitation tool referenced as being used to extract ADFS token-signing certificates/keys to enable Golden SAML token forgery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.