All resources
Topic

post-exploitation

2 resources across 1 kinds

Tools

  1. GraphSpyactivehigh-risk

    A browser-based tool for authorized post-compromise operations against Microsoft 365 and Entra ID: it stores and switches between access/refresh tokens and Primary Refresh Tokens, runs device-code flows, browses OneDrive/SharePoint/Outlook/Teams data, enumerates users and roles, and issues arbitrary Microsoft Graph requests. It also supports adding MFA methods (TOTP, FIDO, phone) for account persistence.

    Open ↗
  2. GraphRunneractivehigh-riskdual-use

    A PowerShell post-exploitation toolset for interacting with the Microsoft Graph API after obtaining authenticated access to an Azure AD / M365 account. Provides reconnaissance, persistence, and pillaging modules: email/SharePoint/OneDrive/Teams search and export, malicious app deployment, consent-grant OAuth attacks, security-group cloning, and token refresh, with a browser-based GUI and no third-party dependencies.

    Open ↗