BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: MSCodePhish: Redeem Your Coupon. Surrender Your Sess
 ion\n   Tags: Intro/Beginner | DEF CON Demo Labs | Cloud | Offense/Red Tea
 m |\n   DEF CON Demo Labs\n   When: Saturday\, Aug 8\, 12:00 - 12:45 PDT\n
    Where: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - [1]Map\n\n   Des
 cription:\n\n   MSCodePhish is a redâ€‘team toolkit that turns Microsoftâ€
 ™s Device\n   Code OAuth flow into an embeddable phishing primitive that w
 orks\n   inside any lure (e.g.\, â€śgrab your coupon\,â€ť â€śunlock access
 \,â€ť\n   etc.). Instead of preâ€‘generating device codes and racing again
 st the\n   usual 15â€‘minute timeout\, MSCodePhish exposes a simple API en
 dpoint\n   that phishing pages can call via JavaScript (XHR/fetch) at the 
 exact\n   moment a victim opens the page. The tool then generates a fresh 
 device\n   code on demand\, returns it to the phishing page (e.g.\, render
 ed as a\n   â€ścoupon codeâ€ť)\, and instructs the user to complete the lo
 gin on\n   the legitimate Microsoft device login portal using that code.\n
 \n   Behind the scenes\, MSCodePhish continuously polls Microsoftâ€™s toke
 n\n   endpoint for that device code and\, once the victim finishes\n   aut
 hentication\, captures the resulting refresh token and related\n   claims 
 (tenant\, user\, etc.). From its web UI\, operators can track\n   active c
 ampaigns\, monitor which lures are converting\, and use captured\n   refre
 sh tokens to request new access tokens for different resources\n   (ARM\, 
 Key Vault\, Graph\, Storage\, or custom scopes) in real time.\n   Because 
 the code is generated only when the phishing HTML is actually\n   loaded\,
  MSCodePhish effectively sidesteps deviceâ€‘code expiration\n   issues and
  enables more realistic\, flexible phishing flows that\n   closely mimic\n
 \n   Speakers:Raunak "Trouble1" Parmar\,Chirag "3xpl01tc0d3r" Savla\n\n   
 SpeakerBio:  Raunak "Trouble1" Parmar\n\n   Raunak Parmar works as a senio
 r cloud security engineer at White\n   Knight Labs with 6+ years of experi
 ence. His areas of interest include\n   web penetration testing\, Azure/AW
 S security\, source code review\,\n   scripting\, and development. He enjo
 ys researching new attack\n   methodologies and creating open-source tools
  that can be used during\n   cloud red team activities. He has worked exte
 nsively on Azure and AWS\n   and is the author of Vajra\, AzDevRecon and M
 sCodePhish. He has spoken\n   at multiple respected security conferences l
 ike Black Hat\, Defcon\,\n   Nullcon\, RootCon\, HackspaceCon\, NorthSec\,
  LeHack \, etc and also at\n   local meetups.\n\n   SpeakerBio:  Chirag "3
 xpl01tc0d3r" Savla\n\n   Chirag Savla is a Cyber Security professional wit
 h 10+ years of\n   experience. His areas of interest include penetration t
 esting\, red\n   teaming\, azure and active directory security\, and post-
 exploitation\n   research. He prefers to create open-source tools and expl
 ore new\n   attack methodologies in his leisure. He has worked extensively
  on\n   Azure\, Active Directory attacks\, defense\, and bypassing detecti
 on\n   mechanisms. He is an author of multiple Open Source tools such as\n
    Process Injection\, Callidus\, etc. He has presented at multiple\n   co
 nferences and local meetups and has trained people in international\n   co
 nferences like Blackhat\, BSides Milano\, Wild West Hackinâ€šĂ„Ă´\n   Fest
 .\n\n   Links:\n       GitHub - [2]https://github.com/TROUBLE-1/MSCodePhis
 h\n   '\n\n   1. #LVCCW_Level1_Hall3\n   2. https://github.com/TROUBLE-1/M
 SCodePhish\n\n\n
DTEND:20260808T194500Z
DTSTART:20260808T190000Z
LOCATION:Demo Labs - LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2)
SUMMARY:MSCodePhish: Redeem Your Coupon. Surrender Your Session
END:VEVENT
END:VCALENDAR
