Welcome to our

Cyber Security News Aggregator

.

Cyber Tzar

provide a

cyber security risk management

platform; including automated penetration tests and risk assesments culminating in a "cyber risk score" out of 1,000, just like a credit score.

AiTM for WHFB persistence

published on 2025-04-30 17:09:19 UTC by /u/rikvduijn
Content:

We recently ran an internal EntraIDiots CTF where players had to phish a user, register a device, grab a PRT, and use that to enroll Windows Hello for Business—because the only way to access the flag site was via phishing-resistant MFA.

The catch? To make WHFB registration work, the victim must have performed MFA in the last 10 minutes.In our CTF, we solved this by forcing MFA during device code flow authentication. But that’s not something you can do in a real-life red team scenario.

So we asked ourselves: how can we force a user we do not controlll to always perform MFA? That’s exactly what this blog explores.

submitted by /u/rikvduijn
[link] [comments]
Article: AiTM for WHFB persistence - published 5 months ago.

https://www.reddit.com/r/netsec/comments/1kblr3u/aitm_for_whfb_persistence/   
Published: 2025 04 30 17:09:19
Received: 2025 04 30 17:17:22
Feed: /r/netsec - Information Security News and Discussion
Source: /r/netsec - Information Security News and Discussion
Category: Cyber Security
Topic: Cyber Security
Views: 26

Custom HTML Block

Click to Open Code Editor