cloudap

sekurlsa::cloudap lists Azure (Primary Refresh Token) credentials based on the following research: Digging further into the Primary Refresh Tokenarrow-up-right. According to Benjaminarrow-up-right:

  • Azure API does not verify ctx replay

  • Azure relies on symmetric keys

  • Software or TPM keys are "protected" by legacy DPAPI

  • AzureAd logon must support device key for legacy DPAPI

circle-exclamation
mimikatz # sekurlsa::cloudap

The following screenshot was borrowed from this tweetarrow-up-right:

Azure session key dump

Last updated