Yuya Chudo

Yuya Chudo is a red team technical lead at Secureworks Japan K.K. He specializes in red team testing and vulnerability assessment, and has been working in the field of cyber security for around 7 years. He has found multiple zero-day vulnerabilities in famous network products and and he has presented his research at Black Hat Asia 2024 Briefings and Black Hat Europe 2024 Briefings. You can find him on X (formerly known as Twitter) @TEMP43487580


Session

06-25
14:15
60min
Hopping Accross Devices: Expanding Lateral Movement through Pass-the-Certificate Attack
Yuya Chudo

Lateral movement is one of the key factors in Red Team engagements. While various attack methods exist in Active Directory environments, the options for lateral movement are limited in Entra ID-based environments. However, the Pass-the-Certificate attack technique introduced by @rubin_mor in 2020 remains a valid option. Through reverse engineering of undocumented features in Windows, we have confirmed that this technique can be extended to multiple protocols and can be used to gain access to Entra-joined devices. In some scenarios, it is even possible to bypass MFA restrictions to move laterally across devices.

In this presentation, we will share insights into the mechanism of lateral movement using P2P certificates, present attack scenarios with a demo, and introduce a new tool for compromising Entra-joined devices with multi-protocol support. Finally, we will highlight the risks posed by this technique and discuss security measures for Entra ID-based enterprise infrastructure.

Active Directory & Entra ID Security
Track 2 (AD & Entra ID Sec)