Manual certificate rotation with disabled automatic rollover can leave stale records in the WID database while valid keys persist in Machine DPAPI. This drift creates a 'ghost' entry that hides the true signing key from common extraction paths but remains exploitable by privileged actors.
The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI
Monitor Event ID 385 to detect configuration drift and enforce automated certificate management for safer key lifecycle handling.
Read the original at Google Cloud — Threat Intelligence →
Subscribe
Short, high-signal articles and news summarized — at a frequency of your choosing. One click to subscribe.