SAML/SSO Providers Integration
Overview
SAML enables single sign-on across enterprise applications. KYRA MDR collects authentication events from SAML identity providers for monitoring SSO activity and detecting anomalies. Supports ADFS, PingFederate, and Shibboleth.
Prerequisites
- A KYRA MDR Collector installed and running
- SAML Identity Provider (IdP) with administrative access
- Audit logging enabled on the IdP
- Network connectivity from the IdP server to the collector
Configuration
Configure SAML IdP audit logging:
For ADFS:
Set-AdfsProperties -AuditLevel Verboseauditpol /set /subcategory:"Application Generated" /success:enable /failure:enableForward ADFS events using NXLog:
<!-- nxlog.conf --><Input adfs> Module im_msvistalog Query <QueryList><Query><Select Path="Security">*[System[Provider[@Name='AD FS Auditing']]]</Select></Query></QueryList></Input><Output out> Module om_tcp Host <collector-ip> Port 514</Output>For PingFederate, configure under System > Audit Log with syslog output.
Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Authentication | SSO login events | Access monitoring |
| Token Issuance | SAML assertion generation | Session creation tracking |
| Token Validation | Assertion validation events | Token abuse detection |
| Federation | Federation trust events | Trust configuration monitoring |
| Claims | Claim transformation events | Attribute mapping auditing |
| Errors | Authentication failure events | Attack detection |
Troubleshooting
No ADFS events: Ensure ADFS auditing is set to Verbose level.
Missing SSO events: Authentication events are generated by the IdP, not the Service Provider.
PingFederate: PingFederate audit logs are written to files by default. Configure syslog output.
Contact kyra@seekerslab.com for support.