Unpacking the AAD Broker LocalState Cache
ID: 27d62a06-8d12-5b13-958f-240d7d030d2c
STIX ID: report--27d62a06-8d12-5b13-958f-240d7d030d2c
Feed Name: SpecterOps Blog
This technical post maps the Azure AD Broker (Entra ID) LocalState cache, reverses its packing/encryption (UTF-8 BOM + version tag, Base64 ASN.1 DPAPI/CNG, zlib), and documents JSON vs. custom binary serialization used for PRT and per-application authority files; it demonstrates how to decrypt/unpack these caches to recover PRT session key material and JWTs, and highlights security risks including potential silent token renewal and long-lived access when attackers have local SYSTEM/TPM-bound key access, as well as the reconnaissance value of exposed identity, application, and token metadata.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
