Maestro : Chris Thompson :

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • number6
    404 Image not found
    • Apr 2019
    • 2172

    #1

    Maestro : Chris Thompson :

    Title: Maestro
    Presenter: Chris Thompson
    Co-Presenter:
    Location: W303
    Day,Time: Sat Aug 10 , 10AM - 11:45AM
    Audience: Offense, Cloud
    Project: https://github.com/Mayyhem/Maestro

    Abstract:
    Maestro is a post-exploitation tool designed to interact with Intune/EntraID from a C2 agent on a user's workstation without requiring knowledge of the user's password or Azure authentication flows, token manipulation, and web-based administration console. Maestro makes interacting with Intune and EntraID from C2 much easier, as the operator does not need to obtain the user's cleartext password, extract primary refresh token (PRT) cookies from the system, run additional tools or a browser session over a SOCKS proxy, or deal with Azure authentication flows, tokens, or conditional access policies in order to execute actions in Azure on behalf of the logged-in user. Maestro enables attack paths between on-prem and Azure. For example, by running Maestro on an Intune admin's machine, you can execute PowerShell scripts on any enrolled device without ever knowing the admin's credentials!

    Bios:
    * Presenter:
    Chris Thompson (@_Mayyhem) is a Principal Consultant at SpecterOps, where he conducts red team operations, research, tool development, and training. Chris has instructed at Black Hat USA/EU and spoken at Arsenal, DEF CON Demo Labs, SO-CON, and Troopers. He is the primary author of Maestro and SharpSCCM and co-author of Misconfiguration Manager, an open-source tool and knowledge base that can be used to help demonstrate, mitigate, and detect attacks that abuse Microsoft Configuration Manager (formerly SCCM).
    * Co-Presenter:
    Starts
    August 10, 2024 10:00
    Ends
    August 10, 2024 11:45
    Location
    W303
    Last edited by number6; June 25, 2024, 16:02.
  • Mayyhem
    Member
    • Aug 2022
    • 2

    #2
    Here is a link to the slides from my presentation today in case you missed it: https://docs.google.com/presentation...f=true&sd=true

    Thanks to everyone who came out!
    -Chris

    Comment

    Working...