本文にスキップ

SAML/SSO Providers Integration

Overview

SAML enables single sign-on across enterprise applications. KYRA MDR collects authentication events from SAML identity providers for monitoring SSO activity and detecting anomalies. Supports ADFS, PingFederate, and Shibboleth.

Prerequisites

  • A KYRA MDR Collector installed and running
  • SAML Identity Provider (IdP) with administrative access
  • Audit logging enabled on the IdP
  • Network connectivity from the IdP server to the collector

Configuration

Configure SAML IdP audit logging:

For ADFS:

Terminal window
Set-AdfsProperties -AuditLevel Verbose
auditpol /set /subcategory:"Application Generated" /success:enable /failure:enable

Forward ADFS events using NXLog:

<!-- nxlog.conf -->
<Input adfs>
Module im_msvistalog
Query <QueryList><Query><Select Path="Security">*[System[Provider[@Name='AD FS Auditing']]]</Select></Query></QueryList>
</Input>
<Output out>
Module om_tcp
Host <collector-ip>
Port 514
</Output>

For PingFederate, configure under System > Audit Log with syslog output.

Collected Log Types

Log TypeDescriptionSecurity Use
AuthenticationSSO login eventsAccess monitoring
Token IssuanceSAML assertion generationSession creation tracking
Token ValidationAssertion validation eventsToken abuse detection
FederationFederation trust eventsTrust configuration monitoring
ClaimsClaim transformation eventsAttribute mapping auditing
ErrorsAuthentication failure eventsAttack detection

Troubleshooting

No ADFS events: Ensure ADFS auditing is set to Verbose level.

Missing SSO events: Authentication events are generated by the IdP, not the Service Provider.

PingFederate: PingFederate audit logs are written to files by default. Configure syslog output.

Contact kyra@seekerslab.com for support.