Entra Device Code Phishing

Entra ID OAuth device-code phishing for token theft, illicit consent grant via malicious app registration with delegated Graph scopes, refresh-token replay, and primary-refresh-token (PRT) abuse concepts.

purpleailab 567c2be 7.0 KB Updated

File contents

purpleailab/decepticon/tree/main/packages/decepticon/decepticon/skills/standard/cloud/entra-device-code-phishing commit 567c2bef51

Frequently asked questions

npx skillmds@latest add purpleailab/entra-device-code-phishing