Attacking OAUTH With Device Code Phishing

Execute OAuth 2.0 device-code and illicit-consent phishing attacks against Microsoft Entra ID to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365 services during authorized red-team engagements.

mukul975 Updated 24.6k repo stars

File contents

mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/attacking-oauth-with-device-code-phishing commit 673da1f3b0

Frequently asked questions

npx skillmds@latest add mukul975/attacking-oauth-with-device-code-phishing