Attacking OAUTH With Device Code Phishing

Run OAuth 2.0 device-code and illicit-consent phishing attacks against Microsoft Entra ID, using TokenTactics-style tooling to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365 services. Use for authorized red-team engagements simulating device-code or consent-grant phishing against a tenant you have explicit written permission to test.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/attacking-oauth-with-device-code-phishing commit 023bdd5785

Frequently asked questions

npx skillmds@latest add gabrielmoreira/attacking-oauth-with-device-code-phishing