PRT Abuse from Userland with Cobalt Strike
This page describes how to acquire an Azure AD Single Sign-On session from a non-privileged user session on a Windows machine. The acquired token is later used to enumerate Azure AD via ROADTools.
Introduction
Primary Refresh Tokens (PRTs)

Requesting PRTs



From PRT to Access Token




Enumerating Azure AD via RoadRecon


Detection
Conclusion
References
Last updated