# The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI

> Quelle: Google/Mandiant Threat Intel · Google Cloud Blog — https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi/

## Maßnahmen

- [ ] Betroffenheit im eigenen Stack prüfen: Versionen/Komponenten abgleichen.
- [ ] Originalquelle / Hersteller-Advisory lesen: https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi/
- [ ] Verfügbaren Patch oder Workaround einspielen und dokumentieren.
