Living off Microsoft Copilot - Michael Bargury @OWASPGLOBAL
Living off Microsoft Copilot - Michael Bargury  @OWASPGLOBAL
Uploaded March 2025 | Updated September 2026, 3 weeks ago
owasp2024globalappsecsanfra.sched.com/event/1g3Wa/living-off-microsoft-copilot

Whatever your need as a hacker post-compromise, Microsoft Copilot has got you covered. Covertly search for sensitive data and parse it nicely for your use. Exfiltrate it out without generating logs. Most frightening, Microsoft Copilot will help you phish to move lately. Heck, it will even social engineer victims for you!

This talk is a comprehensive analysis of Microsoft copilot taken to red-team-level practicality. We will show how Copilot plugins can be used to install a backdoor into other user’s copilot interactions, allowing for data theft as a starter and AI-based social engineering as the main course. We’ll show how hackers can circumvent built-in security controls which focus on files and data by using AI against them.

Next, we will drop LOLCopilot, a red-teaming tool for abusing Microsoft Copilot as an ethical hacker to do all of the above. The tool works with default configuration in any M365 copilot-enabled tenant.

Finally, we will recommend detection and hardening your can put in place to protect against malicious insiders and threat actors with Copilot access.

-

Managed by the OWASP® Foundation
owasp.org
Living off Microsoft Copilot - Michael BarguryEvolving Threat Modeling Through the Open Threat Model Format - Fraser ScottOWASP Corporate Supporter Spotlight - root.ioOne Cluster to Rule Them All: Pentesting Multi-Tenant Kubernetes ClustersOWASP Finance - Full Summary Readout May 2026OWASP Dependency Track Fortifying The Supply Chain - Aravind Parappil & Vinod AnandanAI and API Security PanelOWASP AIBOM: Pioneering AI Transparency Through Community-Driven StandardsUsing an Application Performance Monitoring (APM) Environment for Security InsightsPrivacy by Design: What Are Engineers Supposed to Do With That?SBOMs in the Real World: Practical Guidance for Managing Three Common SBOM ScenariosInfluencing Without Authority: The Foundations of a Successful Security Department of Yes
OWASP Foundation |

Living off Microsoft Copilot - Michael Bargury

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER