Deceptive SAML IdP

Goal: To gather information about attackers attempting to exploit SAML vulnerabilities and detect their presence.

Approach: Monitoring access to the deceptive SAML IdP and analyzing attacker behavior.

Attackers who attempt to use the fake SAML IdP for authentication or authorization will be misled, and their actions will be logged.

Engage Goals: EGO0001 Expose, EGO0003 Elicit

Engage Approach: EAP0001 Collect, EAP0002 Detect

Engage Actions: EAC0015 Information Manipulation, EAC0018 Security Controls

Name of Element: Deceptive SAML IdP

Description of Element:

Goal: To gather information about attackers attempting to exploit SAML vulnerabilities and detect their presence.

Approach: Monitoring access to the deceptive SAML IdP and analyzing attacker behavior.

Attackers who attempt to use the fake SAML IdP for authentication or authorization will be misled, and their actions will be logged.

Technical Context:

This element can be combined with other deceptive elements, such as fake accounts or deceptive network configurations, to enhance its effectiveness. It aligns with the MITRE ATT&CK technique T1606 (Compromise Accounts).

Other:

This element involves setting up a fake SAML IdP that mimics a legitimate service but includes unexpected assertions or attributes in the SAML response.

Leave a Reply