Title:Azure Active Directory Hybrid Health AD FS New Server Status:test Description:This detection uses azureactivity logs (Administrative category) to identify the creation or update of a server instance in an Azure AD Hybrid health AD FS service.
A threat actor can create a new AD Health ADFS service and create a fake server instance to spoof AD FS signing logs. There is no need to compromise an on-prem AD FS server.
This can be done programmatically via HTTP requests to Azure.
References: -https://o365blog.com/post/hybridhealthagent/ Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC Date: 2021-08-26 modified:2023-10-11 Tags:
-'attack.defense-impairment'
-'attack.t1578'
Logsource:
product: azure
service: activitylogs
Detection: selection: CategoryValue:
'Administrative' ResourceProviderValue:
'Microsoft.ADHybridHealthService' ResourceId|contains:
'AdFederationService' OperationNameValue:
'Microsoft.ADHybridHealthService/services/servicemembers/action' condition:selection Falsepositives:
-Legitimate AD FS servers added to an AAD Health AD FS service instance Level:medium