BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Tokens and PRT: Advanced Attacks and Persistence in 
 Microsoft\n   Entra ID\n   Tags: Red Team Village | Misc\n   When: Sunday\
 , Aug 9\, 10:00 - 11:59 PDT\n   Where: LVCCW Level 1 Hall 1 309 (Red Team 
 Village) Tactic Table 1 -\n   [1]Map\n\n   Description:\n\n   Is MFA and C
 onditional Access a real security guarantee? In this\n   technical session
 \, we will demonstrate how endpoint compromise allows\n   an attacker to b
 ypass traditional identity barriers in the cloud. The\n   talk focuses on 
 exploiting vulnerabilities in Microsoft Entra ID\,\n   breaking down an ad
 vanced attack chain:\n\n   • Device Code Flow: Abuse of authentication f
 lows for initial access\n   (Demo with Entraith). • PowerShell Hijacking
 : Process interception\n   to obtain session tokens (GrabTokenAzureAD). 
  Sliver BOF\n   Extraction: Use of Beacon Object Files (BOF) for stealthy
  exfiltration\n   of tokens and the Primary Refresh Token (PRT) from memor
 y\, evading\n   anti-malware defenses. • MFA Bypass and Intune: The spea
 kers\n   developed custom tooling to extract local PRTs\, bypass Intune de
 vice\n   management controls\, and circumvent MFA. This entire attack life
 cycle\n   was consolidated into Entraith — an offensive framework built 
 from\n   scratch by the research team and set to be released publicly at D
 EF\n   CON 34 (https://github.com/bl4cksku11/entraith) — enabling device
 \n   code attacks\, token renewal\, email and app inspection\, token\n   e
 xfiltration\, and persistence generation from a single interface.\n\n   Th
 is talk is not about a single CVE or a niche edge case. It is a\n   compre
 hensive offensive research presentation covering the full\n   spectrum of 
 attack techniques against Microsoft Entra ID — from the\n   very first f
 oothold to deeply rooted\, multi-vector persistence that\n   survives inci
 dent response.\n\n   We will demonstrate\, live\, how an attacker moves th
 rough every phase\n   of an Entra ID compromise:\n\n   INITIAL ACCESS AND 
 TOKEN THEFT: We begin with Device Code Flow\n   phishing — abusing Micro
 soft’s own authentication protocol to\n   harvest valid tokens without e
 ver touching a password. We then\n   escalate with PowerShell process hija
 cking (GrabTokenAzureAD) to\n   intercept live session tokens\, and culmin
 ate with Sliver BOF-based\n   extraction of the Primary Refresh Token (PRT
 ) directly from memory —\n   stealthy\, silent\, and anti-malware evasiv
 e. These three techniques\n   alone demonstrate that MFA and Conditional A
 ccess are not the\n   guarantees organizations believe them to be.\n\n   B
 YPASSING INTUNE AND MFA: Purpose-built tools developed during this\n   res
 earch extract local PRTs\, bypass Intune device compliance controls\,\n   
 and circumvent MFA enforcement at the token layer — not through\n   soci
 al engineering\, but through direct abuse of Microsoft’s identity\n   pl
 atform mechanics. Attackers operating from non-enrolled or\n   non-complia
 nt devices can achieve full Tenant access that Conditional\n   Access poli
 cies are designed to prevent.\n\n   PERSISTENCE ACROSS 10 VECTORS: Once in
 side\, we deploy a “Survival\n   Kit” of 10 chained persistence mechan
 isms — camouflaged App\n   Registrations\, long-lived secrets and certif
 icates\, backdoor accounts\,\n   strategic role assignments\, privileged g
 roup inheritance\, admin\n   mailbox delegation\, inbox-rule-based exfiltr
 ation of credentials and\n   MFA codes\, OAuth consent grants to external 
 applications\, and\n   Temporary Access Pass generation for on-demand MFA 
 bypass. No single\n   blue team action — password reset\, MFA enforcemen
 t\, device wipe —\n   removes all of them simultaneously.\n\n   ENTRAITH
  — BUILT BY US\, RELEASED AT DEF CON: The centerpiece of this\n   talk i
 s Entraith (https://github.com/bl4cksku11/entraith)\, an\n   offensive fra
 mework designed and built from the ground up by the\n   speakers specifica
 lly for this research. Entraith is not a wrapper\n   around existing tools
  — it is original work\, developed over months\n   of hands-on red team 
 engagements against real Microsoft 365\n   environments. It unifies every 
 technique demonstrated in this talk\n   into a single operator interface: 
 device code phishing\, PRT extraction\n   from memory\, Intune compliance 
 bypass\, token renewal and exfiltration\,\n   email and application enumer
 ation\, and the full 10-step persistence\n   deployment chain. DEF CON 34 
 will be the moment Entraith is released\n   to the public. Attendees will 
 be among the first to access the tool\,\n   its documentation\, and the fu
 ll methodology behind it — making this\n   talk a genuine first-look at 
 original research with immediate\n   real-world impact.\n\n   WHY THIS MAT
 TERS FOR CLOUD VILLAGE: The Microsoft 365 and Entra ID\n   ecosystem is th
 e identity backbone of the majority of enterprise\n   organizations worldw
 ide. The techniques presented here are not\n   theoretical — they are be
 ing used by real threat actors today.\n   Defenders in the room will leave
  with concrete detection opportunities\n   and an understanding of exactly
  which log sources and control gaps\n   allow this attack chain to succeed
  undetected. Red teamers will leave\n   with a working tool and a fully do
 cumented methodology. This talk\n   delivers both offensive depth and defe
 nsive utility in a single\n   session\, and the live demos ensure no atten
 dee has to take our word\n   for it.\n\n   Speakers:Elzer Pineda\,Jose Riv
 as\n\n   SpeakerBio:  Elzer Pineda\, Pentester\n\n   Regional Pentester an
 d Cybersecurity Consultant\, Elzer Pineda is an\n   active member of the R
 ed Team executing strategic consulting projects\n   and advanced penetrati
 on testing engagements. His career has been\n   focused on Threat Research
  for private and government organizations\n   across the region. He is a D
 ojo Community Ambassador and Professor at\n   the Universidad Tecnológica
  de Panamá (UTP). His experience has\n   taken him to share technical res
 earch at Ekoparty\, BSides Latam Peru\,\n   BSides Panamá\, DOJOConf\, Pw
 nedCR\, and OWASP Latam. Offensive security\n   certifications: OSWE\, OSE
 P\, OSCP\, OSWP\, CRTP\, CRTO\, and CRTL.\n\n   --\n\n   Profesor en la Un
 iversidad Tecnológica de Panamá y especialista en\n   Red Team con más 
 de 10 años de experiencia en ciberseguridad\n   ofensiva y defensiva. Pen
 tester en GBM (región y Estados Unidos) y\n   researcher en Toad Security
 . Máster en Seguridad Informática.\n   Realiza evaluaciones de seguridad
  a aplicaciones móviles\, web e\n   infraestructura en Latinoamérica y c
 omparte activamente conocimientos\n   en la comunidad Dojo como embajador 
 y conferencias. Certificaciones:\n   OSWE\, OSEP\, OSCP\, CRTO\, OSWP\, CR
 TL.\n\n   SpeakerBio:  Jose Rivas\, Experienced Penetration Tester at A-LI
 GN\n\n   Jose Rivas is an Offensive Security Researcher and Red Team Opera
 tor\n   at A-LIGN\, specializing in adversarial simulations\, Active Direc
 tory\n   attack paths\, and physical security assessments. Co-founder of Z
 ero\n   Trust Offsec\, an offensive security research group focused on\n  
  vulnerability exploitation\, emerging attack techniques\, and\n   respons
 ible disclosure\, and Founder of DCG Panama\, Panama's first\n   official 
 DEF CON chapter\, where he leads a community dedicated to red\n   team ope
 rations\, and adversarial tradecraft. A recognized voice in the\n   Panama
 nian security community\, Jose has spoken at BSides Colombia\,\n   BSides 
 Panama\, OWASP Panama\, and DOJOConf. With certifications\n   including CR
 TO\, eWPT\, eCPPT\, and CompTIA PenTest+\, he brings a\n   threat-actor mi
 ndset and a strong commitment to advancing offensive\n   security knowledg
 e across the region.\n\n   Jose Manuel Rivas is a Penetration Tester and R
 ed Team Operator at\n   A-LIGN\, with hands-on experience in adversarial s
 imulations\, Active\n   Directory attack chains\, web application testing\
 , and physical\n   security assessments. He has multiple CVEs to his name\
 , discovered\n   through bug bounty programs and independent vulnerability
  research.\n   Co-founder of Zero Trust Offsec and founder of DCG Panama\,
  Panama's\n   first official DEF CON chapter. He has spoken at BSides Colo
 mbia\,\n   BSides Panama\, OWASP Panama\, and DOJOConf\, and is focused on
  growing\n   the penetration testing and red team culture across Latin Ame
 rica.\n\n   '\n\n   1. #LVCCW_Level1_Hall1\n\n\n
DTEND:20260809T185900Z
DTSTART:20260809T170000Z
LOCATION:Red Team Village - LVCCW Level 1 Hall 1 309 (Red Team Village) Tac
 tic Table 1
SUMMARY:Tokens and PRT: Advanced Attacks and Persistence in Microsoft Entra
  ID
END:VEVENT
END:VCALENDAR
