Premium Only Content

GraphSpy - Device Code Token Theft Made Easy
In this video, I walk you through GraphSpy, a powerful reconnaissance and attack tool for Microsoft 365 (M365) Entra (formerly Azure AD). Designed for security researchers and penetration testers, GraphSpy automates token abuse, privilege escalation, and identity reconnaissance within cloud environments. Whether you're testing for misconfigurations or simulating real-world attacks, this tool provides deep insights into OAuth abuse, over-permissioned applications, and tenant-wide security weaknesses.
We cover:
✅ Installation & Setup – How to get GraphSpy running
✅ Usage & Features – A deep dive into reconnaissance and attack capabilities
✅ Practical Demonstration – How to leverage GraphSpy for security testing
This tool is a must-know for security researchers and penetration testers working with Entra AD and M365 environments.
Chapters:
0:00 - Welcome to SYNACK Time
2:00 - Installing Python and GraphSpy
5:00 - Using GraphSpy to steal tokens
19:10 - Outtro
Resources:
GraphSpy Blog - https://insights.spotit.be/2024/04/05/graphspy-the-swiss-army-knife-for-attacking-m365-entra/
GraphSpy Github - https://github.com/RedByte1337/GraphSpy
Disabling Device Code Authentication - https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-block-authentication-flows
Right of Boom talks about Device Code Logins
https://www.youtube.com/watch?v=QGdonY59DWc
SYNACK Time - https://synacktime.com
SYNACK Time github - https://github.com/SynAckTime/
#GraphSpy #Microsoft365 #EntraID #Cybersecurity #PenTesting #RedTeam #BlueTeam #OffensiveSecurity #EthicalHacking #CloudSecurity #AzureAD #OAuth #SecurityResearch #BugBounty #BlueTeamTools #RedTeamTools #CloudPenTesting #IAMSecurity #CyberThreats #HackerTools
-
LIVE
Lofi Girl
3 years agolofi hip hop radio 📚 - beats to relax/study to
185 watching -
56:38
DeProgramShow
2 days agoDeprogram with Ted Rall and John Kiriakou: "Jake Tapper on the Global Hunt for an Al Qaeda Killer”
27.4K6 -
16:30
GritsGG
2 days agoWarzone's New Zombie Royal Mode is AWESOME!
3.21K2 -
1:43:07
The Michelle Moore Show
3 days ago'The 12 Open Doors' Guest, Steve Jarvis: The Michelle Moore Show (Oct 17, 2025)
35.2K13 -
30:55
TruthStream with Joe and Scott
7 days agoTruthStream in Ireland, Rebels Across the Pond, Bono discussed, with Freedom Now Acoustic from a Pub
7.2K12 -
3:12:34
Badlands Media
1 day agoThe Narrative Ep. 43: Unity.
346K82 -
2:43:11
TheSaltyCracker
9 hours agoWe Kill You Rally ReeEEStream 10-19-25
93.9K251 -
7:54:17
Putther
14 hours ago $27.55 earned🔴LAZY SUNDAY STREAM!! (GTA + MORE)
77K12 -
10:38
Colion Noir
8 hours agoHe Installed a Forced Reset Trigger at a Gun Range… and Got Arrested | What You Need to Know
59.8K23 -
1:29:26
HELMETFIRE
8 hours ago🟢GAMING WITH FIRE EP13🟢
31.3K5