Weaponization of Token Theft – A Red Team Perspective
ID: 0ffbd4fa-4005-5f96-8d13-603baab37822
STIX ID: report--0ffbd4fa-4005-5f96-8d13-603baab37822
Feed Name: TrustedSec blog
Threat Score
This blog outlines offensive techniques for stealing and weaponizing Microsoft 365 tokens: phishing with Evilginx to capture session cookies, using TokenTactics/TokenTacticsV2 to obtain access/refresh tokens, leveraging ROADtools/GraphRunner/AzureHound for data collection, and exploiting roadtx to create/enrich Primary Refresh Tokens and bypass Entra ID join/trustType conditional access—resulting in potential long-lived, persistent access to tenant resources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
