The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI

Published 2026-07-07T14:00:00Zc31ad9b12c764b12186792b2de391c045d9a9204ce0bbaafd3be1cdd4059ab98

Source metadata

Publication date
2026-07-07T14:00:00Z
Source identifier
https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi/
Public record ID
record:sha256:c31ad9b12c764b12186792b2de391c045d9a9204ce0bbaafd3be1cdd4059ab98

This is source-provided metadata, not an enriched summary or an impact assessment. Follow the canonical source link for the published material.

Evidence and limitations

Source ID
mandiant_threat_intelligence
Record identifier
c31ad9b12c764b12186792b2de391c045d9a9204ce0bbaafd3be1cdd4059ab98
Record type
Source metadata

This record may overlap with other records. Source metadata can be incomplete or change. Validate consequential decisions against the linked source and your own environment.