The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI
Published 2026-07-07T14:00:00Z•c31ad9b12c764b12186792b2de391c045d9a9204ce0bbaafd3be1cdd4059ab98
Source metadata
- Publication date
- 2026-07-07T14:00:00Z
- Source identifier
- https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi/
- Public record ID
- record:sha256:c31ad9b12c764b12186792b2de391c045d9a9204ce0bbaafd3be1cdd4059ab98
This is source-provided metadata, not an enriched summary or an impact assessment. Follow the canonical source link for the published material.
Evidence and limitations
- Source ID
- mandiant_threat_intelligence
- Record identifier
- c31ad9b12c764b12186792b2de391c045d9a9204ce0bbaafd3be1cdd4059ab98
- Record type
- Source metadata
This record may overlap with other records. Source metadata can be incomplete or change. Validate consequential decisions against the linked source and your own environment.