{"repo":"SpecterOps/pass-the-passkey","free":true,"listed":false,"github":"https://github.com/SpecterOps/pass-the-passkey","clone":"git clone https://github.com/SpecterOps/pass-the-passkey.git","description":"Pass-the-Passkey Family of Attacks","language":"C#","stars":196,"topics":["dotnet","entra-id","fido2","passkeys","security-tools","webauthn","windows"],"license":"MIT","category":"security-tools","readme_excerpt":"Pass-the-Passkey Family of Attacks This repository contains a collection of tools and resources related to the Pass-the-Passkey family of attacks, which target WebAuthn and FIDO2 authentication mechanisms in Windows and were featured in the Black Hat USA 2026 talk. These tools are designed for security researchers and penetration testers to assess the security of systems that use passkey-based authentication. [!WARNING] The techniques described in this repository are intended for educational purposes only. Unauthorized use of these procedures may violate laws and regulations. Tools Passkey Injector The Passkey Injector is a simple web browser built on the Edge WebView2 control that intercepts WebAuthn assertion requests and allows responses to be injected in JSON format. There are multiple use cases for tampering with the passkey authentication flow, including: - Replay of captured assertions from network traffic, API hooks, or browser logs. - Phishing attacks by forwarding attacker-controlled assertions. - Injection of modified assertions to test server-side validation. - Signing challenges using stolen synchronized passkeys, e.g., from KeePassXC or Bitwarden. - Analysis of WebAuthn features and extensions used by a particular cloud service. - Learning how the WebAuthn protocol works. SharpPasskeys Tool This tool is a .NET Framework 4.8 assembly designed to be executed as a payload by a Windows C2 agent like Apollo, part of the Mythic C2 framework. The main purpose of this p","default_branch":null,"files":null,"tree":[],"storefront":"/r/SpecterOps","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/SpecterOps/pass-the-passkey/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}