Federated Once, Owned Forever - When Federation Trust Becomes the Credential
Stress-testing Azure Federated Identity Credentials and how a rogue issuer can become a silent authentication path to an existing managed identity without changing RBAC.
Stress-testing Azure Federated Identity Credentials and how a rogue issuer can become a silent authentication path to an existing managed identity without changing RBAC.
OAuth Permission Grants Abuse in Microsoft Entra ID - Attack Path Analysis and MITRE ATT&CK Mapping.
A practical guide to FOCI-driven token reuse, demonstrating how token reuse can be abused under realistic conditions and how to mitigate it.
A practical guide to FOCI-driven token reuse, focusing on token types and storage locations across selected Microsoft applications.
A deep dive in Azure Key Vault bypass options ...