
From Initial Access to Persistence: Abusing Synced Passkeys in Azure | Hacker Summer 2026
Source: YouTube · Altered Security · published Jul 20, 2026 · 1:38:08
This webinar demonstrates how attackers can register passkeys as a persistence mechanism after phishing credentials, bypassing traditional incident response procedures 0:59.
Key Takeaways:
• The attack captures SSO tokens via EvilGinx, then uses a webhook to an Azure Function App to automatically register a new passkey stored in Key Vault—without stealing the victim's existing passkey 8:37, 12:20
• Traditional IR playbooks (password reset + session revocation) fail because they don't remove registered passkeys, allowing attackers to regain access immediately 9:54, 10:29
• Passkeys have no expiration, making them more persistent than certificates—similar to SSH keys that remain valid indefinitely 10:41
• Key defenses include enforcing FIDO attestation, requiring phishing-resistant authentication via Conditional Access, and securing the registration process with device context requirements 43:54, 48:04
• Organizations should implement audit log monitoring for passkey registration events and update IR playbooks to explicitly remove registered authentication methods 1:15:35, 1:16:16
As passkeys become the default authentication method, defenders must adapt both prevention controls and response procedures to address this emerging persistence vector.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Hey, everyone! See if we can get this going here. Make sure everybody can hear me, okay? Because I can't hear. And. Kept telling me I was
in a different meeting so you can hear me. Okay. Perfect. That is excellent. Cool. Well, hopefully
this helps the scraggly hear a little bit, and we'll give it just a second. And so I get a couple other things
set up. Awesome. Thanks, guys. Cool. Let me pull this up. Hopefully that'll work. Can see everything. Great. All right. Well I'm going to go and get
started the webinar for today. From initial access to persistence, we're
going to be taking a look at Passkeys, how they can be registered as an attacker
and then used in very interesting ways. Before we get started too much though, I want to thank Altar Security
for hosting the webinar. You know, putt…