Elzer Pineda PA·Jose Manuel Rivas PA Tokens and PRT: Advanced Attacks and Persistence in Microsoft Entra ID
Is MFA and Conditional Access a real security guarantee? In this technical session, we will demonstrate how endpoint compromise allows an attacker to bypass traditional identity barriers in the cloud. The talk focuses on exploiting vulnerabilities in Microsoft Entra ID, breaking down an advanced attack chain:
- Device Code Flow: Abuse of authentication flows for initial access (Demo with Entraith).
- PowerShell Hijacking: Process interception to obtain session tokens (GrabTokenAzureAD).
- Sliver BOF Extraction: Use of Beacon Object Files (BOF) for stealthy exfiltration of tokens and the Primary Refresh Token (PRT) from memory, evading anti-malware defenses.
- MFA Bypass and Intune: Custom tools were developed to extract local PRTs, bypass Intune device management controls, and circumvent MFA. The entire process was automated through the open-source tool https://github.com/bl4cksku11/entraith, enabling attacks via device code flow, token renewal, email and app inspection, token exfiltration, and persistence generation.
ResearchersElzer Pineda PA·Jose Manuel Rivas PA