Module 8 Links and Resources PASS THE PRT Dirk Jan's Blog about PRT: https://dirkjanm.io/abusing-azure-ad-sso-with-the-primary-refresh-token/ Primary Refresh Tokens https://learn.microsoft.com/en-us/azure/active-directory/devices/concept-primary-refresh-token ROADTOKEN https://github.com/dirkjanm/ROADtoken RequestAADRefreshToken - Lee Christensen https://github.com/leechristensen/RequestAADRefreshToken/ _________________ PASS THE COOKIE Cookie Decode (Feel free to use another tool) https://github.com/byt3bl33d3r/OffensiveNim/blame/master/src/chrome_dump_bin.nim Previous Write-ups on Mimikatz method: https://www.coresecurity.com/core-labs/articles/reading-dpapi-encrypted-keys-mimikatz https://blog.netwrix.com/2022/11/29/bypassing-mfa-with-pass-the-cookie-attack/ _________________ ABUSING MANAGED IDENTITIES Managed Identities: https://learn.microsoft.com/en-us/azure/active-directory/managed-identities-azure-resources/overview @DebugPrivilege Blog: https://m365internals.com/2021/11/30/lateral-movement-with-managed-identities-of-azure-virtual-machines/ Tripla.dk WriteUp: https://tripla.dk/2022/03/13/create-an-azure-vulnerable-lab-part-4-managed-identities/