PE-SHI
shimit
CyberArk's proof-of-concept for the Golden SAML attack — forges a signed SAMLResponse to mint an AWS console session as any federated user.
OVERVIEW
shimit (github.com/cyberark/shimit) is a Python proof-of-concept from CyberArk's research team implementing the Golden SAML attack: with an Identity Provider's SAML signing private key and certificate in hand, an attacker can construct and sign an arbitrary SAMLResponse asserting they are any user with any set of claims — without touching the IdP, MFA, or any credential belonging to that user.
Its current implementation targets AWS as the Service Provider: shimit builds the forged assertion, signs it with the supplied key/certificate, and calls the AWS `AssumeRoleWithSAML` API directly with that response to obtain temporary AWS credentials for the chosen role — which can then be dropped straight into the AWS CLI. The README notes AWS support is a proof of concept and other SAML-federated service providers (beyond AWS) are left for the community to add.
USE CASES
Practical use cases
- 01
Proving Golden SAML impact against AWS once a red team engagement has compromised an ADFS signing key/certificate.
- 02
Illustrating why SAML IdP signing key material deserves the same protection as domain admin credentials.
- 03
Minting temporary AWS credentials for a chosen role/session name to demonstrate unrestricted account access.
- 04
Validating whether CloudTrail and SIEM detections flag an `AssumeRoleWithSAML` call backed by a forged assertion.
QUICK START
In post-exploitation, once an ADFS (or other SAML IdP) signing certificate and private key have been compromised, to prove that compromise grants unrestricted access to federated AWS accounts.
- Clone the repository and install its Python dependencies.
- Confirm the engagement has already recovered the target ADFS/IdP's SAML signing private key (PEM) and certificate (PEM) — shimit does not extract these itself.
- Identify the target AWS account ID, the IdP's trust/issuer URL, and the federated role name to assume.
- Run shimit with the key, certificate, target user, role, and account ID to sign a forged SAMLResponse and call `AssumeRoleWithSAML`.
- Export the returned temporary AWS access key, secret key, and session token into the AWS CLI to confirm the session works.
python shimit.py -idp http://adfs.lab.local/adfs/services/trust -pk key.pem -c cert.pem -u domain\admin -n admin@domain.com -r ADFS-admin -id 123456789012BEFORE YOU RUN IT
What to check before running it
shimit assumes the hardest part — stealing the IdP's SAML signing private key — is already done; it is a post-exploitation/impact-demonstration tool, not a way to obtain that key.
A forged `AssumeRoleWithSAML` call still lands in AWS CloudTrail under the assumed role's session — align with the client on expected activity and have a rollback/rotation plan for the compromised signing certificate.
Rotating the IdP's SAML signing certificate immediately invalidates every session mintable via this technique — recommend certificate rotation as remediation, not just password resets.