Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Windows Hello Abuse: Exploiting Authentication and Security Features

Ekoparty Security Conference via YouTube

Overview

Explore a comprehensive security conference talk that delves into vulnerabilities and potential exploits within Windows Hello and Windows Hello for Business (WHFB) authentication systems. Learn about advanced attack vectors including WHFB key provisioning during phishing scenarios, device code phishing, and credential phishing techniques. Discover how Windows Hello keys are protected and utilized on Windows devices, with detailed insights into leveraging these keys for lateral movement and maintaining persistence after gaining access to user sessions. Building upon previous findings that revealed gaps in Microsoft's promoted security features, examine how these passwordless authentication methods can be compromised without MFA and exploited for movement between Entra ID and on-premises Active Directory through cloud Kerberos trust.

Syllabus

Windows Hello abuse, the sequel - Dirk-jan Mollema - Ekoparty 2024

Taught by

Ekoparty Security Conference

Reviews

Start your review of Windows Hello Abuse: Exploiting Authentication and Security Features

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.