Video wird geladen...
Video konnte nicht geladen werden
A security researcher (Dirk-jan) just dropped a new technique for abusing Windows Hello for Business keys from a compromised user session. No admin rights. No PIN. No biometrics. Full persistence into Entra ID cloud from a user-level implant. KQL detection query included. If you do anything with Active Directory,... show more
48,577 Aufrufe • vor 1 Monat •via X (Twitter)
3 Kommentare

Jon Towles {MVP}vor 1 Monat
@_dirkjan the man

Greg Kutzbach, CISSPvor 1 Monat
I want whfb or any hardware bound authentication to be local to the device. I don’t want that device proxied or relayed elsewhere. At that point, lets just call a spade a spade and use a totp or similar auth. They took something good then made it weak for convenience. /r

Tom Sweetvor 1 Monat
So this is actively exploitable?

