Plan
active
Malware Can Abuse Windows Hello for Business Keys for Entra ID Persistence
- Engineer — Plan: This post-exploitation technique lets malware silently leverage WHfB keys to register attacker-controlled devices and obtain PRTs in Entra ID tenants. Audit Conditional Access policies to enforce device compliance checks for sensitive operations and restrict who can register new devices in your tenant.
- SOC/IR — Plan: The technique has a clear Entra ID audit-log surface: build detections on anomalous device registrations and PRT issuances in Microsoft Entra sign-in and audit logs, particularly where the registering session doesn’t match expected device inventory.
- Leader — Learn: Published research reveals a persistence path through Microsoft’s cloud identity stack that could let an endpoint compromise extend into long-lived Entra ID access; no active exploitation or breach is reported, so no immediate leadership action is needed.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.