pushsecurity / saas-attacks

Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face. #nolockdown
https://pushsecurity.com/blog/saas-attack-techniques/
Creative Commons Attribution 4.0 International
943 stars 61 forks source link

Add AITM phishing proxying as a techinique #43

Closed jukelennings closed 3 months ago

jukelennings commented 9 months ago

Exploitation of this and defences against it are becoming more common and is probably worth consideration for inclusion in the matrix.

Another interesting example that may be better off as a separate defence evasion technique is using noVNC to bypass protections:

https://mrd0x.com/bypass-2fa-using-novnc/