Michael Bargury: No-Code Malware — Abusing Power Automate in Windows 11
A DEF CON 30 talk about how the built-in Windows 11 automation tool Power Automate can be abused to conduct attacks without writing traditional malware.
The presentation demonstrates the full attack chain: distributing payloads, bypassing security controls, executing on victim machines, and exfiltrating data — using only built-in and signed Windows components along with Office cloud services.
The presentation demonstrates the full attack chain: distributing payloads, bypassing security controls, executing on victim machines, and exfiltrating data — using only built-in and signed Windows components along with Office cloud services.