Tool · cloudactivehigh-risk
GraphSpy
A browser-based tool for authorized post-compromise operations against Microsoft 365 and Entra ID: it stores and switches between access/refresh tokens and Primary Refresh Tokens, runs device-code flows, browses OneDrive/SharePoint/Outlook/Teams data, enumerates users and roles, and issues arbitrary Microsoft Graph requests. It also supports adding MFA methods (TOTP, FIDO, phone) for account persistence.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
High risk of account lockouts, WAF bans, and terms-of-service violations. Requires explicit authorization and small, targeted inputs.
More tools
- AzureHoundcloudSpecterOps's Go data collector that enumerates Microsoft Azure/Entra tenant data and formats it for BloodHound to map attack paths and privilege-escalation routes. It supports multiple auth methods (username/password, JWT, refresh tokens, Azure CLI), runs as a CLI or persistent service, and ships cross-platform binaries.
- PacucloudAn open-source AWS exploitation framework by Rhino Security Labs with a modular architecture for enumeration, privilege escalation, IAM user backdooring, Lambda exploitation, lateral movement, data exfiltration, and log manipulation. It tracks enumerated data in a local SQLite database and logs commands for audit trails.
- agent-chaperoneagent-guardrailApache-2.0 MCP proxy and Claude Code hooks adapter that screens an agent's tool calls before they run and tool results before it reads them against thresholds in a policy file; log-only by default, needs a TypeSafe API key.
- AI Vuln Scannerdast/web-app-scannerA security research CLI that automates web-application vulnerability scanning with OWASP ZAP (spider + active attack) and uses the Anthropic Claude API to analyze findings and generate Markdown remediation reports. Ships an intentionally vulnerable Flask app as a safe test target.
- Aktoapi-securityOpen-source API-security platform with a large BOLA/IDOR/broken-auth test library, usable as an independent authorization cross-check.
- AmassreconDeep passive subdomain enumeration across many public sources.