Forge Web Credentials: SAML Tokens T1606.002
Tactic: Credential Access
An adversary may forge SAML tokens with any permissions claims and lifetimes if they possess a valid SAML token-signing certificate. The default lifetime of a SAML token is one hour, but the validity period can be specified in the NotOnOrAfter value of the conditions ... element in a token. This value can be changed using the AccessTokenLifetime in a LifetimeTokenPolicy. Forged SAML tokens enable adversaries to authenticate across services that use SAML 2.0 as an SSO (single sign-on) mechanism.
Authoring guide
These 2 rules share fields, values, and exclusions.
Fields filtered most (11 distinct)
These fields appear most often in rule filters.
Top indicator values (36 distinct)
These values appear most often in rule predicates.
Rules under this technique
These vendors publish rules tagged with this technique.