Premium Only Content

GraphSpy - Device Code Token Theft Made Easy
In this video, I walk you through GraphSpy, a powerful reconnaissance and attack tool for Microsoft 365 (M365) Entra (formerly Azure AD). Designed for security researchers and penetration testers, GraphSpy automates token abuse, privilege escalation, and identity reconnaissance within cloud environments. Whether you're testing for misconfigurations or simulating real-world attacks, this tool provides deep insights into OAuth abuse, over-permissioned applications, and tenant-wide security weaknesses.
We cover:
✅ Installation & Setup – How to get GraphSpy running
✅ Usage & Features – A deep dive into reconnaissance and attack capabilities
✅ Practical Demonstration – How to leverage GraphSpy for security testing
This tool is a must-know for security researchers and penetration testers working with Entra AD and M365 environments.
Chapters:
0:00 - Welcome to SYNACK Time
2:00 - Installing Python and GraphSpy
5:00 - Using GraphSpy to steal tokens
19:10 - Outtro
Resources:
GraphSpy Blog - https://insights.spotit.be/2024/04/05/graphspy-the-swiss-army-knife-for-attacking-m365-entra/
GraphSpy Github - https://github.com/RedByte1337/GraphSpy
Disabling Device Code Authentication - https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-block-authentication-flows
Right of Boom talks about Device Code Logins
https://www.youtube.com/watch?v=QGdonY59DWc
SYNACK Time - https://synacktime.com
SYNACK Time github - https://github.com/SynAckTime/
#GraphSpy #Microsoft365 #EntraID #Cybersecurity #PenTesting #RedTeam #BlueTeam #OffensiveSecurity #EthicalHacking #CloudSecurity #AzureAD #OAuth #SecurityResearch #BugBounty #BlueTeamTools #RedTeamTools #CloudPenTesting #IAMSecurity #CyberThreats #HackerTools
-
17:35
Actual Justice Warrior
1 day agoDMV Workers CAUGHT Selling CDL Tests To Migrants
14.4K27 -
13:24
Dr Disrespect
3 days agoFirst Day of Battlefield 6 with DrDisrespect
73.5K24 -
2:54:42
Side Scrollers Podcast
19 hours agoEA BANNING “MAGA” Usernames? + Roblox CP Situation Gets WORSE+ CollarGate + More | Side Scrollers
43.6K40 -
15:09
GritsGG
15 hours agoSolo Warzone Victory! Shadow Banned!
15.9K -
LIVE
Lofi Girl
3 years agolofi hip hop radio 📚 - beats to relax/study to
267 watching -
12:19
BlabberingCollector
1 day agoPotter Fans In Frenzy, Keira Knightly Responds To Potter Involvement Backlash | Wizarding World News
16.3K1 -
2:56:20
FreshandFit
14 hours agoThe Price Is Right! Fresh&Fit After Hours Edition
206K80 -
6:45
The Power of Connection
2 days agoThe Power of Connection : Networking vs. Connecting
17.3K4 -
28:53
Afshin Rattansi's Going Underground
3 days agoTrump Has Surrounded Himself With Neocons AGAIN, War After War is Coming! (James Carden)
23.9K21 -
1:54:50
Badlands Media
13 hours agoDevolution Power Hour Ep. 398: Economic Warfare, Trump’s Strategy, and the Coming Reckoning
80.8K34