Stealing OAuth Tokens Through Microsoft's Front Door
A sideloaded package turns a Microsoft-signed binary into an OAuth token theft tool. No phishing domain, no spoofed UI, no browser. Here's how to detect it.
Energetic and driven, Andrew Schwartz is a Principal Detection Engineering & Threat Hunting Analyst at Huntress with extensive expertise in offensive and defensive security, vulnerability management, and transformational strategies that help organizations detect and stop adversaries before they succeed. A published researcher with a focus on Active Directory security, specifically Kerberos, LDAP, and DACL-based attack detection, Andrew is notably the co-author of the Kerberos Diamond Ticket attack.
His passion for security started at a young age, sparked by classic action, crime, and spy movies alongside a fascination with global security agencies and current events. As a kid, he spent countless hours reading weekly issues of Time and Newsweek from cover to cover, which ultimately inspired his early career in investigative roles supporting federal and local law enforcement.
Andrew's drive to continually evolve within InfoSec shows in his commitment to continuous learning. Whether reading, following industry research, taking specialized training courses, or engaging with colleagues across the security community, he stays at the forefront of emerging threats and security tools. Outside of building detections and analyzing new attack vectors, Andrew enjoys playing chess, cheering on Tottenham Hotspur, and crafting the perfect Old Fashioned or Boulevardier.
A sideloaded package turns a Microsoft-signed binary into an OAuth token theft tool. No phishing domain, no spoofed UI, no browser. Here's how to detect it.
An AD RMS Service Group account exports the AD RMS Server Licensor Certificate private key. That 1172-byte key decrypts every document the deployment ever protected, offline, and keeps doing so after the deployment is rebuilt.
Active Directory Rights Management Services still ships in Windows Server 2025, years after Microsoft began steering customers to the cloud, and it remains fully supported on-premises. Part 1 maps the AD RMS trust model (the Server Licensor Certificate, the license flow, the SOAP surface) and shows how to discover an RMS deployment, fingerprint an AD RMS-protected file, and trace the path to that certificate's private key.
ldapnomnom claims it leaves no Windows audit logs. This post shows why Event 1644 misses LDAP Ping and where defenders can still catch it.
The same NTLM leakage primitive that got patched in the Snipping Tool exists in Windows Explorer's search: handler. No CVE. No fix. If your patching relies on CVE coverage, you have a blind spot.
A fully patched Windows Server 2025 domain is vulnerable to dMSA Ouroboros—a self-sustaining credential extraction technique requiring only standard delegated permissions. Learn how it works, why remediation fails, and how to detect it.