SpecterOps invites you to their event

The Red Teamer’s Guide to Passkeys

About this event

Passkeys are quickly becoming a widely adopted approach to phishing-resistant authentication, but they also introduce new attack paths for adversaries to explore. In this session, we’ll examine Pass-the-Passkey, a novel and actively researched category of malware-initiated attack techniques targeting passkey authentication that can enable cloud user impersonation.

We’ll walk through practical passkey attacks, including passkey phishing, authentication prompt flooding and originator spoofing, syncable passkey theft, browser process WebAuthn API hooking, event log mining, and Windows Hello for Business credential hijacking. Along the way, we’ll explore what these techniques mean for both offensive operators and defenders as passkeys become more common across enterprise environments.

Attendees will learn:

  • How malware-initiated attacks can target passkey authentication to impersonate cloud users
  • Practical techniques for attacking passkeys across browsers, endpoints, and cloud environments
  • New privilege escalation, reconnaissance, and persistence tradecraft for red team operators
  • Where defenders should look for exposure and opportunities to detect passkey-focused attacks

Hosted by

  • Team member
    T
    Michael Grafnetter Principal Security Researcher @ SpecterOps

SpecterOps

Know your adversary

SpecterOps provides adversary-focused cybersecurity solutions and training, enabling organizations to understand and defend against the tactics of threat actors through tradecraft analysis and attack path management.