
SeamlessPass: Leveraging Kerberos tickets to get Microsoft 365 access tokens meterpreter.org/seamlesspass-l…
Malcrove - Next Generation Security
14 posts

@malcrove
Malcrove is a cyber security firm dedicated to protecting government and private enterprise throughout MENA against the latest cyber threats.

SeamlessPass: Leveraging Kerberos tickets to get Microsoft 365 access tokens meterpreter.org/seamlesspass-l…

I guess 6% of respondents are fibbing here.. The machine account hash for AZUREADSSOACC is a tier one asset in your organization, if compromised the attacker can impersonate any account in azure (tickets generated offline) and you have very very poor visibility of this in logs



Registration for the #HITB2021SIN #HITBCyberWeek PRO CTF Qualifiers is now open! Organized by @hackerdom in collaboration with @CTFae and HITB, this CTF is specifically for students from universities and other educational establishments. Register here: conference.hitb.org/hitbsecconf202…


Big thanks to @malcrove and @CTFae from not only us for the CTF, but @CtgIntelligence for the hoodie!














