Premium Only Content

GraphSpy - Device Code Token Theft Made Easy
In this video, I walk you through GraphSpy, a powerful reconnaissance and attack tool for Microsoft 365 (M365) Entra (formerly Azure AD). Designed for security researchers and penetration testers, GraphSpy automates token abuse, privilege escalation, and identity reconnaissance within cloud environments. Whether you're testing for misconfigurations or simulating real-world attacks, this tool provides deep insights into OAuth abuse, over-permissioned applications, and tenant-wide security weaknesses.
We cover:
✅ Installation & Setup – How to get GraphSpy running
✅ Usage & Features – A deep dive into reconnaissance and attack capabilities
✅ Practical Demonstration – How to leverage GraphSpy for security testing
This tool is a must-know for security researchers and penetration testers working with Entra AD and M365 environments.
Chapters:
0:00 - Welcome to SYNACK Time
2:00 - Installing Python and GraphSpy
5:00 - Using GraphSpy to steal tokens
19:10 - Outtro
Resources:
GraphSpy Blog - https://insights.spotit.be/2024/04/05/graphspy-the-swiss-army-knife-for-attacking-m365-entra/
GraphSpy Github - https://github.com/RedByte1337/GraphSpy
Disabling Device Code Authentication - https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-block-authentication-flows
Right of Boom talks about Device Code Logins
https://www.youtube.com/watch?v=QGdonY59DWc
SYNACK Time - https://synacktime.com
SYNACK Time github - https://github.com/SynAckTime/
#GraphSpy #Microsoft365 #EntraID #Cybersecurity #PenTesting #RedTeam #BlueTeam #OffensiveSecurity #EthicalHacking #CloudSecurity #AzureAD #OAuth #SecurityResearch #BugBounty #BlueTeamTools #RedTeamTools #CloudPenTesting #IAMSecurity #CyberThreats #HackerTools
-
2:21:57
MattMorseTV
3 hours ago $60.07 earned🔴Trump's EMERGENCY Oval Office ANNOUNCEMENT.🔴
99.4K48 -
1:08:13
Michael Franzese
2 hours agoEric Trump and Michael Franzese: When The Government Attacks Your Family (Exclusive Sitdown)
15.9K6 -
1:20:43
vivafrei
4 hours agoLive with Shawn Farash! Trump Impersonator and Conservative Activist! Viva Frei Interviews!
108K24 -
1:43:44
The Quartering
4 hours agoFat Acceptance Is So Over, Church Attendance Surges, Tim Pool Water, D&D Is Full Woke Trash!
118K23 -
LIVE
LFA TV
20 hours agoBREAKING: JOHN BOLTON INDICTED! | THURSDAY 10/16/25
1,392 watching -
LIVE
freecastle
5 hours agoTAKE UP YOUR CROSS- Don't be deceived: God isn't mocked, for whatever one sows, will he also reap!
157 watching -
1:10:28
The White House
3 hours agoPresident Trump Makes an Announcement, Oct. 16, 2025
30.9K29 -
3:49:52
Right Side Broadcasting Network
7 hours agoLIVE: President Trump Makes an Announcement - 10/16/25
110K31 -
LIVE
StoneMountain64
5 hours agoBattlefield 6 is just TOO FUN
213 watching -
14:51
Dr. Nick Zyrowski
3 days agoWho Should Follow A Low Carb Diet? (Surprising Answer!)
22.6K3