Skip to content

Adding PRT capabilities#10

Open
fjodoin wants to merge 2 commits intoabsolomb:mainfrom
fjodoin:main
Open

Adding PRT capabilities#10
fjodoin wants to merge 2 commits intoabsolomb:mainfrom
fjodoin:main

Conversation

@fjodoin
Copy link
Copy Markdown

@fjodoin fjodoin commented May 4, 2026

Attackers may add fake devices to Entra/Intune upon successfully phishing a target. If this is done through Device Code Phishing, the attacker may never obtain access to the cleartext credentials of the victim.

The fake device can be used to obtain PRTs. It is important for defenders to understand where Network Restrictions are missing on CAPs. Fake devices (and their PRTs) can potentially spoof Compliance, Hybrid, Passwordless, etc. authentication contexts.

This vibe-coded and tested branch adds the PRT functionality, allowing defenders to spray PRTs; Attackers can also perform CAP bruteforcing using PRTs without ever obtaining the victim's cleartext passwords.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant