logo

Weaponization of Token Theft – A Red Team Perspective

ID: 0ffbd4fa-4005-5f96-8d13-603baab37822

STIX ID: report--0ffbd4fa-4005-5f96-8d13-603baab37822

Feed Name: TrustedSec blog

Threat Score
70/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This blog outlines offensive techniques for stealing and weaponizing Microsoft 365 tokens: phishing with Evilginx to capture session cookies, using TokenTactics/TokenTacticsV2 to obtain access/refresh tokens, leveraging ROADtools/GraphRunner/AzureHound for data collection, and exploiting roadtx to create/enrich Primary Refresh Tokens and bypass Entra ID join/trustType conditional access—resulting in potential long-lived, persistent access to tenant resources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.