Loading video...
Video Failed to Load
A security researcher (Dirk-jan) just dropped a new technique for abusing Windows Hello for Business keys from a compromised user session. No admin rights. No PIN. No biometrics. Full persistence into Entra ID cloud from a user-level implant. KQL detection query included. If you do anything with Active Directory,... show more
48,577 views • 1 month ago •via X (Twitter)
3 Comments

Jon Towles {MVP}1 month ago
@_dirkjan the man

Greg Kutzbach, CISSP1 month ago
I want whfb or any hardware bound authentication to be local to the device. I don’t want that device proxied or relayed elsewhere. At that point, lets just call a spade a spade and use a totp or similar auth. They took something good then made it weak for convenience. /r

Tom Sweet1 month ago
So this is actively exploitable?

