
Guard me if you can: A Novel Passwordless-to-Password attack | SO-CON 26
Source: YouTube · SpecterOps · published Jun 4, 2026 · 35:49
The speakers introduce a novel attack technique dubbed "Got Me If You Can," which exploits passwordless authentication flows to facilitate password-based attacks 0:02-0:06.
Key Takeaways:
• Yuichiro, a Fujitsu security consultant, provides red team services in Japan and has a background in developing new offensive tools 0:12-0:33.
• Riku introduces Credential Guard as a specific focus area for their upcoming technical discussion 0:37-0:44.
• The core agenda of the session is to explain how attackers can abuse and manipulate passwordless authentication mechanisms 0:52-0:56.
This presentation outlines the foundational concepts needed to understand how modern passwordless systems can be leveraged to enable traditional credential attacks.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Hello everyone. Welcome to our talk, "Got Me If You Can." An novel passwordless to password attack. So, uh it's okay. First, let us introduce ourselves. So, my name is Yuichiro and I am a security consultant at Fujitsu and I provide red team services against various organizations in Japan. And during during engagements, we often find new techniques or we develop new tools. So, we have been sharing them in the past like by token broker or the Python stuff. Yeah. >> Hello everyone. Thank you for coming. My name is Riku. I'm really excited to be here and talk about credential guard today. >> Okay, so here is the agenda for this session. Today, we would like to discuss how we can abuse the passwordless authentication flow, which is mainly about the Windows Hello for Business to bypass the cred…