M365 red-team platform device-code phishing, token harvesting, service-token minting, in-panel data collection and SOCKS5 reverse tunneling
-
Updated
Sep 7, 2026 - PowerShell
M365 red-team platform device-code phishing, token harvesting, service-token minting, in-panel data collection and SOCKS5 reverse tunneling
Walkthrough of an authorized cloud red-team CTF I solved: OAuth device-code phishing, token theft, Microsoft Graph and SharePoint enumeration, exfiltration. Plus the KQL hunts and Conditional Access policy that catch it.
Defender-focused analysis of a Microsoft 365 device-code phishing campaign (OAuth device-authorization abuse, MFA-bypassing) - defanged IOCs, Entra hunting, no live samples.
Microsoft Entra device code phishing detection lab for Sentinel and Defender XDR
To associate your repository with the device-code-phishing topic, visit your repo's landing page and select "manage topics."