Tools
Tool · post-exploitationactivehigh-riskdual-use

GraphRunner

A PowerShell post-exploitation toolset for interacting with the Microsoft Graph API after obtaining authenticated access to an Azure AD / M365 account. Provides reconnaissance, persistence, and pillaging modules: email/SharePoint/OneDrive/Teams search and export, malicious app deployment, consent-grant OAuth attacks, security-group cloning, and token refresh, with a browser-based GUI and no third-party dependencies.

Use responsibly

Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.

High risk of account lockouts, WAF bans, and terms-of-service violations. Requires explicit authorization and small, targeted inputs.

More tools