All resources
Topic

m365

4 resources across 1 kinds

Tools

  1. ShareFiltratoractivedual-usehigh-risk

    A Python CLI that uses the SharePoint search API to discover and bulk-download files across SharePoint/OneDrive in an M365 tenant, targeting documents exposed by over-permissive sharing that may contain credentials or secrets. Uses authenticated browser session cookies and ships preset queries (Snaffpoint, Credentials).

    Open ↗
  2. GraphSpyactivehigh-risk

    A browser-based tool for authorized post-compromise operations against Microsoft 365 and Entra ID: it stores and switches between access/refresh tokens and Primary Refresh Tokens, runs device-code flows, browses OneDrive/SharePoint/Outlook/Teams data, enumerates users and roles, and issues arbitrary Microsoft Graph requests. It also supports adding MFA methods (TOTP, FIDO, phone) for account persistence.

    Open ↗
  3. GraphRunneractivehigh-riskdual-use

    A PowerShell post-exploitation toolset for interacting with the Microsoft Graph API after obtaining authenticated access to an Azure AD / M365 account. Provides reconnaissance, persistence, and pillaging modules: email/SharePoint/OneDrive/Teams search and export, malicious app deployment, consent-grant OAuth attacks, security-group cloning, and token refresh, with a browser-based GUI and no third-party dependencies.

    Open ↗
  4. Monkey365passive

    An open-source PowerShell security assessment framework for Microsoft 365, Azure, and Entra ID that identifies misconfigurations and evaluates cloud posture against CIS benchmarks. Covers workloads like Exchange Online, SharePoint, Teams and Purview, supports multiple auth methods and national clouds, and exports HTML/JSON/CSV reports.

    Open ↗