logo

The Triforce of Initial Access

ID: 1b9f845c-b7ff-562d-9401-45466a21af48

STIX ID: report--1b9f845c-b7ff-562d-9401-45466a21af48

Feed Name: TrustedSec blog

Threat Score
70/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This report outlines a modern offensive workflow targeting Microsoft Entra ID/Office 365: using Evilginx to capture session cookies and bypass MFA, ROADtools to convert cookies into JWT/access-refresh tokens and pivot between resources, and TeamFiltration (with the Bobber automation script) to automate exfiltration of emails, Teams chats, OneDrive and SharePoint files. The document also provides PowerShell examples for leveraging the .roadtools_auth output with various post-exploitation tools (AADInternals, AzureHound, GraphRunner, Power-Pwn) to maximize data collection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.