Clément Notin Profile picture
😈 Security research (#ActiveDirectory #EntraID) & pentest 🎉 #CTF @tipi_hack 👨‍💼 Works @TenableSecurity, opinions my own 🪂 https://t.co/4HRwJQ6PUm
Jan 26 13 tweets 6 min read
What I think happened in the Midnight Blizzard breach of Microsoft: how could they pivot from the test tenant to the production tenant using a OAuth application? 🤔⤵️
microsoft.com/en-us/security… "Midnight Blizzard leveraged their initial access to identify and compromise a legacy test OAuth application that had elevated access to the Microsoft corporate environment."
👀 Assuming we got access to this test tenant and we found this application (aka "app registration") Image