This repository contains research artifacts and reversed-code analysis related to the LocalState cache used by the AAD Broker. The project documents how to fully decrypt the file formats found in the cache. It also implements logic from reverse engineered portions of AAD.Core.dll related to the naming conventions of the cache files.
https://winternl.com/aad-broker-cache
- https://habr.com/ru/articles/688426/
- https://github.com/bl4me/token/wiki/
- https://dirkjanm.io/digging-further-into-the-primary-refresh-token/
Code is released under the MIT license.