WAM BAM - Recovering Web Tokens From Office
ID: 2ae5c2e7-8ce2-5977-8a8b-f308bac8efbb
STIX ID: report--2ae5c2e7-8ce2-5977-8a8b-f308bac8efbb
Feed Name: XPN Infosec Blog
This blog post details how Microsoft Office obtains and caches MSA and Azure AD authentication tokens, showing two recovery methods: calling wlidsvc RPC (e.g., WLIDAcquireTokensWithNGC) to obtain passport tokens for MSA, and locating/decrypting TokenBroker cache files (%LOCALAPPDATA%\Microsoft\TokenBroker\Cache) where Azure/other tokens are serialized and protected with DPAPI. The author provides reversing notes, WinDbg/Ghidra evidence, and proof-of-concept tools (WAMBam) to recover usable JWTs without memory scraping.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
