AuthStrike
1 article
An MFA bypass with no fake login page: the victim completes a real Microsoft sign-in, and the attacker walks away with a live session. Abusing the Authentication Broker client can turn that session into a registered device and a Primary Refresh Token.