logo

WAM BAM - Recovering Web Tokens From Office

ID: 2ae5c2e7-8ce2-5977-8a8b-f308bac8efbb

STIX ID: report--2ae5c2e7-8ce2-5977-8a8b-f308bac8efbb

Feed Name: XPN Infosec Blog

Threat Score
55/100

Date Published: 2022-10-17

Date Updated: 2026-07-30

...
...

This blog post details how Microsoft Office obtains and caches MSA and Azure AD authentication tokens, showing two recovery methods: calling wlidsvc RPC (e.g., WLIDAcquireTokensWithNGC) to obtain passport tokens for MSA, and locating/decrypting TokenBroker cache files (%LOCALAPPDATA%\Microsoft\TokenBroker\Cache) where Azure/other tokens are serialized and protected with DPAPI. The author provides reversing notes, WinDbg/Ghidra evidence, and proof-of-concept tools (WAMBam) to recover usable JWTs without memory scraping.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.