Dylan Bradley
I am a Penetration Tester and Red Teamer from Melbourne with specilisations in Active Directory and Azure / M365. I recently contributed a small amount of research on SCCM to the Misconfiguration Manager Github. I also have an interest in the blue team side of things as I believe it is important to know how to effectively navigate and detect the attacks that I perform. I love having a yap so if you see me around come talk tech or ask me about what I get up to outside the tech world.
Session
In this talk, I'll present my research into the internals of the Microsoft Edge Sync Service, examining how the platform authenticates users, protects synchronized data, and exposes functionality through its backend APIs. We'll begin by exploring Family of Client ID (FOCI) tokens, how they fit into Microsoft's authentication ecosystem, and why they play a critical role in Edge Sync.
From there, we'll dive into the Edge Sync APIs themselves, demonstrating how FOCI tokens can be leveraged to interact directly with synchronization endpoints. We'll examine the structure of synchronized data, the cryptographic protections applied to it, and the mechanisms used to store and transmit sensitive information.
Building on this foundation, I'll demonstrate how synchronization functionality can be abused to extract sensitive data including saved passwords, history and other sync data from a victim's Edge profile.
Finally, I'll reveal a novel technique that leverages the Edge Sync Service to transform a FOCI token into a fully authenticated user session through the acquisition of ESTSAUTH cookies, currently the ONLY known method of performing this type of token-to-session conversion.
Attendees will leave with a deep understanding of Microsoft Edge Sync's architecture, authentication model, data protection mechanisms, and associated attack surface. Defenders will gain practical guidance for identifying, detecting, and mitigating these techniques within Microsoft 365 environments.