Identity Providers for RedTeamers
ID: f417e939-723d-5ddd-b91f-eac7f3aee267
STIX ID: report--f417e939-723d-5ddd-b91f-eac7f3aee267
Feed Name: XPN Infosec Blog
This blog post analyzes post-exploitation techniques targeting identity providers (Okta, OneLogin, Ping, Entra ID), covering LogonUserW hooking to capture credentials, agent-spoofing (recreating AD connector behavior) to harvest plaintext credentials, Kerberos-based approaches (pass-the-cache and silver tickets), SAML external IdP manipulation, phishing leveraging AD connectors, and local FastPass interception on macOS; it includes demonstrations, PoC tools (CloudInject, OneLoginPostExToolkit, PingPostExToolkit, OktaPostExToolkit/OktaRealFast), and emphasizes these are design/implementation weaknesses or misuse rather than new vulnerabilities while noting the need for defenders to detect and mitigate these techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
