Mayyhem / Maestro

Abusing Intune for Lateral Movement over C2

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Sponsored by SpecterOps @_Mayyhem on Twitter


Maestro

Maestro is a post-exploitation tool designed to interact with Intune/EntraID from a C2 agent on a user’s workstation without requiring knowledge of the user’s password or Azure authentication flows, token manipulation, and web-based administration console. Maestro makes interacting with Intune and EntraID (and potentially other Azure services) from C2 much easier, as the operator does not need to obtain the user’s cleartext password, extract primary refresh token (PRT) cookies from the system, run additional tools or a browser session over a SOCKS proxy, or deal with Azure authentication flows, tokens, or conditional access policies in order to execute actions in Azure on behalf of the logged-in user.

DEF CON 32 Demo Labs slides

About

Abusing Intune for Lateral Movement over C2

License:GNU General Public License v3.0


Languages

Language:C# 100.0%