Want some techniques that many Red Teams have been using to circumvent MFA protections on accounts? Yeah, even โunphishableโ versions.
Iโm sharing so that you can think about whatโs coming, how youโll do mitigations, etc. Its being seen in the wild more these days.
๐งต1/n
โ _MG_ (@_MG_) March 23, 2022
MFA is worthless if your user just gives the attacker the MFA code over the phone, as one of the users at a company for which I do consulting decided to do. Yeah, I canโt figure it out either. But the rule of IT is that users are gonna do things you think they will never, ever do, even if youโve told them not to do that very thing repeatedly.