GraphSpy Logo

GraphSpy

GraphSpy is a browser-based post-exploitation tool for Azure Active Directory and Office 365 environments that enables token management, reconnaissance, and interaction with Microsoft 365 services.

1,176
Visit website
Compare
Compare
0
MCPThe entire cybersecurity market, one prompt awayTry MCP Access

GraphSpy Description

GraphSpy is a browser-based post-exploitation tool designed for Azure Active Directory and Office 365 environments. The tool provides security professionals with capabilities to manage access tokens, perform reconnaissance, and interact with Microsoft 365 services after gaining initial access to target systems. The tool offers comprehensive token management functionality, allowing users to store and manage access and refresh tokens for multiple users and scopes. It supports device code authentication flows and provides capabilities to manipulate multi-factor authentication methods for maintaining persistence in compromised environments. GraphSpy includes several modules for post-exploitation activities across Microsoft 365 services. The file access module enables interaction with OneDrive and SharePoint, providing download and upload capabilities for document manipulation. Email functionality allows access and manipulation through Outlook using either direct web access or Graph API integration. The tool supports Microsoft Teams message reading and sending, Graph API searching across Microsoft 365 applications, and custom API request capabilities with template storage for repeated operations. It includes Entra ID user enumeration features for gathering detailed user information during reconnaissance phases. GraphSpy operates as a local web application accessible through standard web browsers, supporting both light and dark modes for user preference. The tool can be installed via pipx and functions across multiple operating systems, with primary testing conducted on Linux and Windows platforms. It supports multiple database configurations to organize tokens and device codes for different assessment engagements.

GraphSpy FAQ

Common questions about GraphSpy including features, pricing, alternatives, and user reviews.

GraphSpy is GraphSpy is a browser-based post-exploitation tool for Azure Active Directory and Office 365 environments that enables token management, reconnaissance, and interaction with Microsoft 365 services.. It is a Security Operations solution designed to help security teams with Post Exploitation, Azure, Reconnaissance.

Have more questions? Browse our categories or search for specific tools.

ALTERNATIVES

CloudCopy Logo

CloudCopy implements a cloud version of the Shadow Copy attack to extract domain user hashes from AWS-hosted domain controllers by creating and mounting volume snapshots.

0

Stay Updated with Mandos Brief

Get strategic cybersecurity insights in your inbox