Premium Only Content

GraphSpy - Device Code Token Theft Made Easy
In this video, I walk you through GraphSpy, a powerful reconnaissance and attack tool for Microsoft 365 (M365) Entra (formerly Azure AD). Designed for security researchers and penetration testers, GraphSpy automates token abuse, privilege escalation, and identity reconnaissance within cloud environments. Whether you're testing for misconfigurations or simulating real-world attacks, this tool provides deep insights into OAuth abuse, over-permissioned applications, and tenant-wide security weaknesses.
We cover:
✅ Installation & Setup – How to get GraphSpy running
✅ Usage & Features – A deep dive into reconnaissance and attack capabilities
✅ Practical Demonstration – How to leverage GraphSpy for security testing
This tool is a must-know for security researchers and penetration testers working with Entra AD and M365 environments.
Chapters:
0:00 - Welcome to SYNACK Time
2:00 - Installing Python and GraphSpy
5:00 - Using GraphSpy to steal tokens
19:10 - Outtro
Resources:
GraphSpy Blog - https://insights.spotit.be/2024/04/05/graphspy-the-swiss-army-knife-for-attacking-m365-entra/
GraphSpy Github - https://github.com/RedByte1337/GraphSpy
Disabling Device Code Authentication - https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-block-authentication-flows
Right of Boom talks about Device Code Logins
https://www.youtube.com/watch?v=QGdonY59DWc
SYNACK Time - https://synacktime.com
SYNACK Time github - https://github.com/SynAckTime/
#GraphSpy #Microsoft365 #EntraID #Cybersecurity #PenTesting #RedTeam #BlueTeam #OffensiveSecurity #EthicalHacking #CloudSecurity #AzureAD #OAuth #SecurityResearch #BugBounty #BlueTeamTools #RedTeamTools #CloudPenTesting #IAMSecurity #CyberThreats #HackerTools
-
10:17
MattMorseTV
16 hours ago $10.55 earnedTrump's DOJ just DROPPED a NUKE.
63.8K73 -
2:09:32
Side Scrollers Podcast
19 hours agoStreamer DIES Live On Air + Your Food is Poison + Xbox Announces $900 Handheld | Side Scrollers Live
19.6K11 -
15:32
GritsGG
15 hours agoFull Auto ABR Sniper Support! Most Winning Quad Win Streaking!
7.82K2 -
7:42
The Pascal Show
14 hours ago $0.41 earnedBREAKING! Police Provide UPDATE In Emmanuel Haro's Case! Is Jake's Lawyer Lying To Us?!
9.21K -
2:29:46
FreshandFit
7 hours agoAfter Hours w/ Girls
108K74 -
5:28
Zach Humphries
13 hours ago $0.90 earnedNEAR PROTCOL AND STELLAR TEAM UP!
15.4K2 -
1:09:57
Brandon Gentile
1 day ago10,000 Hour BITCOIN Expert Reveals Why $13.5M Is Just The Start
20.5K3 -
2:03:55
Badlands Media
8 hours agoDevolution Power Hour Ep. 382: DOJ Coverups, Clapper’s Team Sport & Trump’s Countermoves
133K24 -
2:06:30
Inverted World Live
11 hours agoDon't Approach the Zombie Rabbits | Ep. 95
53.9K24 -
3:26:45
Drew Hernandez
7 hours agoISRAEL PLANNING POSSIBLE DRAFT IN USA & TRUMP'S VIEW ON ETERNAL LIFE ANALYZED PT 2
41.6K50