Skip to main content

Detecting Golden Saml

Status: Scaffold — content in progress

Paired Attack: [Link to attack page]
DRL Level: DRL-3
Detection Confidence: [High / Medium]

Required Telemetry

SourceField / SignalNotes
Entra ID Sign-in log[Key fields]
Entra ID Audit log[Key fields]

Sigma Rule

title: Detecting Golden Saml
status: experimental
# Fill in rule

KQL — Microsoft Sentinel

// Fill in KQL query

False Positive Handling

[Document known benign causes]

TopicLink
Detection Frameworkdetection-framework