Hacking Your Cloud: Tokens Edition 2.0
ID: b88ab3d9-cb51-5f97-a6e1-6e54da17e18c
STIX ID: report--b88ab3d9-cb51-5f97-a6e1-6e54da17e18c
Feed Name: TrustedSec blog
Threat Score
This blog-style report details offensive techniques for obtaining and using Microsoft 365/Azure JWT and refresh tokens to bypass MFA, log into OWA, perform Azure reconnaissance, extract emails and Teams messages, and forge/enrich primary refresh tokens (PRTs). It lists specific tools, commands, and step-by-step procedures that enable credential/token theft and data exfiltration from enterprise tenants.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
