Tools
Tool · cloudactivehigh-risk

GraphSpy

A browser-based tool for authorized post-compromise operations against Microsoft 365 and Entra ID: it stores and switches between access/refresh tokens and Primary Refresh Tokens, runs device-code flows, browses OneDrive/SharePoint/Outlook/Teams data, enumerates users and roles, and issues arbitrary Microsoft Graph requests. It also supports adding MFA methods (TOTP, FIDO, phone) for account persistence.

Use responsibly

Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.

High risk of account lockouts, WAF bans, and terms-of-service violations. Requires explicit authorization and small, targeted inputs.

More tools