AiTM for WHFB persistence

We recently ran an internal EntraIDiots CTF where players had to phish a user, register a device, grab a PRT, and use that to enroll Windows Hello for Business—because the only way to access the flag site was via phishing-resistant MFA. The catch? To …

April 30, 2025
Read More >>