Graphrunner
description
- post-exploitation toolset for microsoft entra ID / o365
- baesd upon microsoft graph API
installation
usage
authentication
- reuse authenticated tokens
- device code or user creds
- azure app auth
recon and enumeration
- gather apps and consent approvals
- dump conditional access policies
- user/groups/sharepoint sites
persistence
- default ability to
- create groups
- invite guests
- create apps
Pillage
Automate Stuff
There is also a GUI
- just a simple HTML site that can be opened with a browser
references