GraphSpy Logo

GraphSpy

GraphSpy is a browser-based post-exploitation tool for Azure Active Directory and Office 365 environments that enables token management, reconnaissance, and interaction with Microsoft 365 services.

816
Security Operations
Free
Visit website
0

GraphSpy Description

GraphSpy is a browser-based post-exploitation tool designed for Azure Active Directory and Office 365 environments. The tool provides security professionals with capabilities to manage access tokens, perform reconnaissance, and interact with Microsoft 365 services after gaining initial access to target systems. The tool offers comprehensive token management functionality, allowing users to store and manage access and refresh tokens for multiple users and scopes. It supports device code authentication flows and provides capabilities to manipulate multi-factor authentication methods for maintaining persistence in compromised environments. GraphSpy includes several modules for post-exploitation activities across Microsoft 365 services. The file access module enables interaction with OneDrive and SharePoint, providing download and upload capabilities for document manipulation. Email functionality allows access and manipulation through Outlook using either direct web access or Graph API integration. The tool supports Microsoft Teams message reading and sending, Graph API searching across Microsoft 365 applications, and custom API request capabilities with template storage for repeated operations. It includes Entra ID user enumeration features for gathering detailed user information during reconnaissance phases. GraphSpy operates as a local web application accessible through standard web browsers, supporting both light and dark modes for user preference. The tool can be installed via pipx and functions across multiple operating systems, with primary testing conducted on Linux and Windows platforms. It supports multiple database configurations to organize tokens and device codes for different assessment engagements.

FEATURED

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Services Logo

Fractional CISO services for B2B companies to accelerate sales and compliance

Stay Updated with Mandos Brief

Get the latest cybersecurity updates in your inbox

POPULAR

RoboShadow Logo

Automated vulnerability assessment and remediation platform

10
TestSavantAI Logo

Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.

5
Cybersec Feeds Logo

A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.

5
Fabric Platform by BlackStork Logo

Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.

5
Mandos Brief Newsletter Logo

A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

5
View Popular Tools →