Premium Only Content

GraphSpy - Device Code Token Theft Made Easy
In this video, I walk you through GraphSpy, a powerful reconnaissance and attack tool for Microsoft 365 (M365) Entra (formerly Azure AD). Designed for security researchers and penetration testers, GraphSpy automates token abuse, privilege escalation, and identity reconnaissance within cloud environments. Whether you're testing for misconfigurations or simulating real-world attacks, this tool provides deep insights into OAuth abuse, over-permissioned applications, and tenant-wide security weaknesses.
We cover:
✅ Installation & Setup – How to get GraphSpy running
✅ Usage & Features – A deep dive into reconnaissance and attack capabilities
✅ Practical Demonstration – How to leverage GraphSpy for security testing
This tool is a must-know for security researchers and penetration testers working with Entra AD and M365 environments.
Chapters:
0:00 - Welcome to SYNACK Time
2:00 - Installing Python and GraphSpy
5:00 - Using GraphSpy to steal tokens
19:10 - Outtro
Resources:
GraphSpy Blog - https://insights.spotit.be/2024/04/05/graphspy-the-swiss-army-knife-for-attacking-m365-entra/
GraphSpy Github - https://github.com/RedByte1337/GraphSpy
Disabling Device Code Authentication - https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-block-authentication-flows
Right of Boom talks about Device Code Logins
https://www.youtube.com/watch?v=QGdonY59DWc
SYNACK Time - https://synacktime.com
SYNACK Time github - https://github.com/SynAckTime/
#GraphSpy #Microsoft365 #EntraID #Cybersecurity #PenTesting #RedTeam #BlueTeam #OffensiveSecurity #EthicalHacking #CloudSecurity #AzureAD #OAuth #SecurityResearch #BugBounty #BlueTeamTools #RedTeamTools #CloudPenTesting #IAMSecurity #CyberThreats #HackerTools
-
1:36:05
Side Scrollers Podcast
19 hours agoStreamer ATTACKS Men Then Cries Victim + Pronoun Rant Anniversary + More | Side Scrollers
80.4K4 -
LIVE
Lofi Girl
2 years agoSynthwave Radio 🌌 - beats to chill/game to
284 watching -
42:55
Stephen Gardner
1 day ago🔥Trump’s SURPRISE Move STUNS Everyone - Democrats PANIC!
102K124 -
1:37:19
Badlands Media
16 hours agoBaseless Conspiracies Ep. 148: The Delphi Murders – Secrets, Setups, and Cover-Ups
47.1K17 -
5:59:05
SpartakusLIVE
10 hours ago#1 MACHINE Never Stops The GRIND || LAST Stream UNTIL Friday
152K3 -
28:36
Afshin Rattansi's Going Underground
1 day agoDoug Bandow: ENORMOUS DAMAGE Done to US’ Reputation Over Gaza, Trump ‘Easily Manipulated’ by Israel
33.4K34 -
2:45:13
Barry Cunningham
17 hours agoCBS CAUGHT AGAIN! CHICAGO A MESS! LISA COOK IS COOKED AND MORE LABOR DAY NEWS!
122K51 -
6:39:17
StevieTLIVE
11 hours agoMASSIVE Warzone Wins on Labor Day w/ Spartakus
37.9K1 -
10:46:42
Rallied
17 hours ago $18.70 earnedWarzone Challenges w/ Doc & Bob
204K4 -
3:26:25
Joe Donuts Live
10 hours ago🟢 Lost in Space with My Clones: The Alters Adventure Begins
40.2K5