I Am AD FS and So Can You - Attacking Active Directory Federated Services
WEareTROOPERS via YouTube
Learn the Skills Netflix, Meta, and Capital One Actually Hire For
Get 20% off all career paths from fullstack to AI
Overview
Syllabus
Intro
Roadmap
Doug Bienstock - @doughsec
Austin Baker - @bakedsec
Active Directory Federated Services
Building Blocks - Claims Pipeline
Building Blocks - Security Tokens
Building Blocks - claims to assertions
Building blocks - the RP
Identity Providers and Adapters
Finding AD FS Proxies
Target the Weak Links
Adapt or die
Windows Internal Database (WID)
Locating the goods
Decrypting the SigningToken
Key Derivation
Key Decryption
ADFSDump
ADFSpoof
Best Practices and Mitigations
Responding Appropriately
Taught by
WEareTROOPERS