Requesting Azure AD Request Tokens
ID: 76d8a46f-5d5f-5cf9-a904-9f6fe449fe3c
STIX ID: report--76d8a46f-5d5f-5cf9-a904-9f6fe449fe3c
Feed Name: SpecterOps Blog
This research details how Windows 10 Accounts/BrowserCore and the MicrosoftAccountTokenProvider COM interface can be leveraged to obtain Azure AD refresh tokens and perform SSO impersonation on Azure AD–joined Windows hosts, then provides defensive telemetry (e.g., MicrosoftAccountTokenProvider.dll load patterns and a specific ETW provider GUID with example trace events) to detect such abuse, underscoring the importance of monitoring new credential sources on Azure AD–integrated endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
