CuraSec

tag: Identity-Persistence · 1 items

  • Engineer — Plan: This post-exploitation technique lets malware silently leverage WHfB keys to register attacker-controlled devices and obtain PRTs in Entra ID tenants. Audit Conditional Access policies to enforce device compliance checks for sensitive operations and restrict who can register new devices in your tenant.
  • SOC/IR — Plan: The technique has a clear Entra ID audit-log surface: build detections on anomalous device registrations and PRT issuances in Microsoft Entra sign-in and audit logs, particularly where the registering session doesn’t match expected device inventory.
  • Leader — Learn: Published research reveals a persistence path through Microsoft’s cloud identity stack that could let an endpoint compromise extend into long-lived Entra ID access; no active exploitation or breach is reported, so no immediate leadership action is needed.