Premium Only Content

GraphSpy - Device Code Token Theft Made Easy
In this video, I walk you through GraphSpy, a powerful reconnaissance and attack tool for Microsoft 365 (M365) Entra (formerly Azure AD). Designed for security researchers and penetration testers, GraphSpy automates token abuse, privilege escalation, and identity reconnaissance within cloud environments. Whether you're testing for misconfigurations or simulating real-world attacks, this tool provides deep insights into OAuth abuse, over-permissioned applications, and tenant-wide security weaknesses.
We cover:
✅ Installation & Setup – How to get GraphSpy running
✅ Usage & Features – A deep dive into reconnaissance and attack capabilities
✅ Practical Demonstration – How to leverage GraphSpy for security testing
This tool is a must-know for security researchers and penetration testers working with Entra AD and M365 environments.
Chapters:
0:00 - Welcome to SYNACK Time
2:00 - Installing Python and GraphSpy
5:00 - Using GraphSpy to steal tokens
19:10 - Outtro
Resources:
GraphSpy Blog - https://insights.spotit.be/2024/04/05/graphspy-the-swiss-army-knife-for-attacking-m365-entra/
GraphSpy Github - https://github.com/RedByte1337/GraphSpy
Disabling Device Code Authentication - https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-block-authentication-flows
Right of Boom talks about Device Code Logins
https://www.youtube.com/watch?v=QGdonY59DWc
SYNACK Time - https://synacktime.com
SYNACK Time github - https://github.com/SynAckTime/
#GraphSpy #Microsoft365 #EntraID #Cybersecurity #PenTesting #RedTeam #BlueTeam #OffensiveSecurity #EthicalHacking #CloudSecurity #AzureAD #OAuth #SecurityResearch #BugBounty #BlueTeamTools #RedTeamTools #CloudPenTesting #IAMSecurity #CyberThreats #HackerTools
-
9:20
daniellesmithab
1 day ago3 Bad Laws
11.2K5 -
9:22
MattMorseTV
16 hours ago $9.09 earnedINDIA just made a BIG MISTAKE.
53.1K51 -
12:11
Nikko Ortiz
14 hours agoCrashout 6 Rumble
8.61K2 -
22:35
GritsGG
14 hours agoThe KILO is BACK! The Best AR on Warzone FRIES!
16.2K1 -
2:16:36
Side Scrollers Podcast
18 hours agoStreamer KICKED OUT of Renaissance Fair for Misgendering + Spiderman MELTDOWN | Side Scrollers Live
39.8K7 -
12:29
The Pascal Show
1 day ago $1.14 earnedLOCKED IN A DUNGEON?! Parents Arrested After 5 Children Found In 'Dungeon' At Home
9.96K3 -
LIVE
Lofi Girl
2 years agoSynthwave Radio 🌌 - beats to chill/game to
230 watching -
3:07:24
FreshandFit
10 hours agoPrivileged Nigerian Thinks Women Created Everything: HEATED DEBATE
146K80 -
5:57:27
SpartakusLIVE
10 hours agoNEW Update - BROKEN Attachment || Viewers REJOICE at the long-awaited Return of Their KING
77.9K -
2:06:31
TimcastIRL
10 hours agoTrump To Deploy National Guard To Portland, Antifa Has Been WIPED OUT | Timcast IRL
195K169