Practical OAuth Abuse for Offensive Operations – Part 1
ID: 9ef5b4d7-8431-5b29-b51a-195af7714518
STIX ID: report--9ef5b4d7-8431-5b29-b51a-195af7714518
Feed Name: TrustedSec blog
This blog post explains OAuth concepts and demonstrates how Microsoft 365/Azure AD authentication flows (notably the device authorization flow and ROPC) can be abused by attackers to obtain access tokens and refresh tokens, enabling persistent access, bypassing some defenses like password changes and leveraging MFA-protected sessions; it also describes attack techniques including social-engineered device login prompts, password spraying, and user enumeration against OAuth endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
