BigHugger
sk Skill · mukul975

attacking-oauth-with-device-code-phishing

Run OAuth 2.0 device-code and illicit-consent phishing attacks against Microsoft Entra ID, using TokenTactics-style tooling to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365 services. Use for authorized red-team engagements simulating device-code or consent-grant phishing against a tenant you have explicit written permission to test.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
jsonPythonred-teamillicit-consentmfa-bypasspowershelltoken-theftoauthbashtokentacticsentra-iddevice-code-phishing
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python