top of page

Blog
Search


PRT Tokens: From Initial Access to Long-Term Cloud Control
Primary Refresh Tokens (PRTs) sit at the core of Azure AD authentication, quietly enabling seamless access across cloud and hybrid environments. While commonly treated as an implementation detail, PRTs represent a powerful attack primitive. Once obtained, they allow an adversary to maintain authenticated access long after initial compromise often surviving password resets, MFA challenges, and user logouts. This post explores how PRT tokens can be abused to move from initial a
Jan 214 min read


Hijacking Azure PowerShell Authentication Flow
While looking into some interesting Azure attacks I came upon something interesting when using the Connect-AzAccount Connect-AzAccount...
Aug 19, 20253 min read


A Day Phishing
Scripting Interpreters Interpreters are a great method to achieve command or shellcode execution Are not Native to Windows Not always...
Jul 23, 20254 min read
bottom of page
