
GraphSpy
GraphSpy is a browser-based post-exploitation tool for Azure Active Directory and Office 365 environments that enables token management, reconnaissance, and interaction with Microsoft 365 services.

GraphSpy
GraphSpy is a browser-based post-exploitation tool for Azure Active Directory and Office 365 environments that enables token management, reconnaissance, and interaction with Microsoft 365 services.
GraphSpy Description
GraphSpy is a browser-based post-exploitation tool designed for Azure Active Directory and Office 365 environments. The tool provides security professionals with capabilities to manage access tokens, perform reconnaissance, and interact with Microsoft 365 services after gaining initial access to target systems. The tool offers comprehensive token management functionality, allowing users to store and manage access and refresh tokens for multiple users and scopes. It supports device code authentication flows and provides capabilities to manipulate multi-factor authentication methods for maintaining persistence in compromised environments. GraphSpy includes several modules for post-exploitation activities across Microsoft 365 services. The file access module enables interaction with OneDrive and SharePoint, providing download and upload capabilities for document manipulation. Email functionality allows access and manipulation through Outlook using either direct web access or Graph API integration. The tool supports Microsoft Teams message reading and sending, Graph API searching across Microsoft 365 applications, and custom API request capabilities with template storage for repeated operations. It includes Entra ID user enumeration features for gathering detailed user information during reconnaissance phases. GraphSpy operates as a local web application accessible through standard web browsers, supporting both light and dark modes for user preference. The tool can be installed via pipx and functions across multiple operating systems, with primary testing conducted on Linux and Windows platforms. It supports multiple database configurations to organize tokens and device codes for different assessment engagements.
FEATURED
Password manager with end-to-end encryption and identity protection features
VPN service providing encrypted internet connections and privacy protection
Fractional CISO services for B2B companies to accelerate sales and compliance
Stay Updated with Mandos Brief
Get the latest cybersecurity updates in your inbox
TRENDING CATEGORIES
POPULAR
Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.