Video yükleniyor...
Video Yüklenemedi
A security researcher (Dirk-jan) just dropped a new technique for abusing Windows Hello for Business keys from a compromised user session. No admin rights. No PIN. No biometrics. Full persistence into Entra ID cloud from a user-level implant. KQL detection query included. If you do anything with Active Directory,... show more
48,577 görüntüleme • 1 ay önce •via X (Twitter)
3 Yorum

Jon Towles {MVP}1 ay önce
@_dirkjan the man

Greg Kutzbach, CISSP1 ay önce
I want whfb or any hardware bound authentication to be local to the device. I don’t want that device proxied or relayed elsewhere. At that point, lets just call a spade a spade and use a totp or similar auth. They took something good then made it weak for convenience. /r

Tom Sweet1 ay önce
So this is actively exploitable?

