Skip to content

Hide Navigation Hide TOC

Azure Active Directory Hybrid Health AD FS New Server (288a39fc-4914-4831-9ada-270e9dc12cb4)

This detection uses azureactivity logs (Administrative category) to identify the creation or update of a server instance in an Azure AD Hybrid health AD FS service. A threat actor can create a new AD Health ADFS service and create a fake server instance to spoof AD FS signing logs. There is no need to compromise an on-prem AD FS server. This can be done programmatically via HTTP requests to Azure.

Cluster A Galaxy A Cluster B Galaxy B Level
Modify Cloud Compute Infrastructure - T1578 (144e007b-e638-431d-a894-45d90c54ab90) Attack Pattern Azure Active Directory Hybrid Health AD FS New Server (288a39fc-4914-4831-9ada-270e9dc12cb4) Sigma-Rules 1