GraphSpy Logo

GraphSpy

GraphSpy is a browser-based post-exploitation tool for Azure Active Directory and Office 365 environments that enables token management, reconnaissance, and interaction with Microsoft 365 services.

816
Visit website
Claim and verify your listing
0

GraphSpy Description

GraphSpy is a browser-based post-exploitation tool designed for Azure Active Directory and Office 365 environments. The tool provides security professionals with capabilities to manage access tokens, perform reconnaissance, and interact with Microsoft 365 services after gaining initial access to target systems. The tool offers comprehensive token management functionality, allowing users to store and manage access and refresh tokens for multiple users and scopes. It supports device code authentication flows and provides capabilities to manipulate multi-factor authentication methods for maintaining persistence in compromised environments. GraphSpy includes several modules for post-exploitation activities across Microsoft 365 services. The file access module enables interaction with OneDrive and SharePoint, providing download and upload capabilities for document manipulation. Email functionality allows access and manipulation through Outlook using either direct web access or Graph API integration. The tool supports Microsoft Teams message reading and sending, Graph API searching across Microsoft 365 applications, and custom API request capabilities with template storage for repeated operations. It includes Entra ID user enumeration features for gathering detailed user information during reconnaissance phases. GraphSpy operates as a local web application accessible through standard web browsers, supporting both light and dark modes for user preference. The tool can be installed via pipx and functions across multiple operating systems, with primary testing conducted on Linux and Windows platforms. It supports multiple database configurations to organize tokens and device codes for different assessment engagements.

GraphSpy FAQ

Common questions about GraphSpy including features, pricing, alternatives, and user reviews.

GraphSpy is GraphSpy is a browser-based post-exploitation tool for Azure Active Directory and Office 365 environments that enables token management, reconnaissance, and interaction with Microsoft 365 services.. It is a Security Operations solution designed to help security teams with Post Exploitation, Azure, Reconnaissance.

Have more questions? Browse our categories or search for specific tools.

FEATURED

Heeler Application Security Auto-Remediation Logo

Fix-first AppSec powered by agentic remediation, covering SCA, SAST & secrets.

Hudson Rock Cybercrime Intelligence Tools Logo

Cybercrime intelligence tools for searching compromised credentials from infostealers

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

Mandos Fractional CISO Logo

Fractional CISO services for B2B companies to build security programs

POPULAR

RoboShadow Logo

Automated vulnerability assessment and remediation platform

13
OSINTLeak Real-time OSINT Leak Intelligence Logo

Real-time OSINT monitoring for leaked credentials, data, and infrastructure

8
Cybersec Feeds Logo

A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.

6
Mandos Brief Logo

Weekly cybersecurity newsletter covering security incidents, AI, and leadership

6
TestSavant AI Security Assurance Platform Logo

AI security assurance platform for red-teaming, guardrails & compliance

5
View Popular Tools →

Stay Updated with Mandos Brief

Get strategic cybersecurity insights in your inbox