logo

Adversary in the Middle (AitM): Post-Exploitation

ID: e3871f80-7bdb-50ed-a898-f51712ce7b8e

STIX ID: report--e3871f80-7bdb-50ed-a898-f51712ce7b8e

Feed Name: Black Hills Infosec Blog

Threat Score
75/100

Date Published: 2024-11-04

Date Updated: 2026-04-27

Author: BHIS

...
...

**Executive summary:** This transcript captures a BHIS webcast detailing post‑exploitation tactics used after adversary‑in‑the‑middle SSO phishing, including creating email rules to suppress alerts, enrolling attacker MFA tokens (prefer TOTP), abusing web VDI/Microsoft cloud PCs for internal access, keeping sessions alive via tab reloading, enumerating/harvesting data via Microsoft Graph tooling (Graph Runner, RoadRecon, Azure Hound), and using device‑code authentication (TokenTactics) to obtain tokens. The presenters describe operational security tradeoffs, real testing success, and provide defensive controls: require MFA reauthentication for enrollment, prefer FIDO2/U2F tokens, disable or monitor device‑code flows, shorten session timeouts, and restrict browser‑based remote access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.