🆕Dump Token Broker Cache
Dump access token for Azure and Microsoft 365 from Token Broker Cache.
Last updated
Dump access token for Azure and Microsoft 365 from Token Broker Cache.
Last updated
You need at least local admin privilege on the remote target, use option --local-auth if your user is a local account
Microsoft 365 and Azure applications on desktop will store access tokens to the Token Broker Cache. These are stored with user DPAPI. You can use the wam
module in order to decrypt them. More info here https://blog.xpnsec.com/wam-bam/