GraphSpy: Hacker's Tooling Deep Dive (w/ creator @RedByte1337!)

GraphSpy: Hacker's Tooling Deep Dive (w/ creator @RedByte1337!)

🎙 John Hammond 👥 2.2M 📅 March 11, 2026 ⏱ 41 min 👁 24K 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

GraphSpyAzure ADdevice code phishingaccess tokenrefresh tokenMFAFIDO2Microsoft Graph API

Summary

In this video, John Hammond interviews Keanu, the developer of GraphSpy, an open-source tool for offensive security assessments against Microsoft Azure and Microsoft 365 environments. The conversation begins with Keanu explaining his background as a penetration tester and the motivation behind creating GraphSpy: the lack of user-friendly tools for working with access tokens obtained through device code phishing. The core of the video is a live demonstration of GraphSpy’s features. Keanu shows how to generate a device code, trick a user into authenticating, and capture their access and refresh tokens. He then demonstrates how to use these tokens to browse OneDrive, SharePoint, and Outlook emails, highlighting the tool’s web-based interface that simplifies API interactions. A significant portion is dedicated to advanced persistence techniques, including using refresh tokens to obtain tokens for different client IDs (via the Family of Client IDs feature) and adding a FIDO2 security key to the victim’s account, effectively granting persistent access. The video also covers MFA method enumeration and modification, and accessing Microsoft Teams messages via the Skype API. Throughout, Keanu emphasizes the real-world applicability and the importance of understanding these attack vectors for both red and blue teams.

193 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides high-value information for cybersecurity professionals, especially those involved in red teaming and penetration testing. It offers a practical, hands-on demonstration of advanced attack techniques against Microsoft cloud services, which are often not covered in standard training. The argumentation is solid, as Keanu explains the underlying mechanisms (e.g., OAuth flows, token scopes, FOCI) and justifies the tool’s design choices. The live demo adds credibility, showing real-time results. However, the discussion is one-sided, with no counterarguments or discussion of defensive measures in depth, which could be seen as a limitation.

Scientific Rigor, Source Quality, Title Accuracy

The video is scientifically rigorous in its technical explanations, but it lacks formal citations to external sources. The primary source is the GraphSpy GitHub repository, which is linked in the description. The title accurately reflects the content, as it is indeed a deep dive into the tool with its creator. The video does not claim to be a peer-reviewed study, but rather a practical tutorial, which is appropriate. The lack of citations is typical for this format, but the information is based on the creator’s expertise and hands-on experience.

195 words

Title / Content Match

The title accurately reflects the content, which is a deep dive into the GraphSpy tool with its creator.

Quality & Reliability

8/10

The video is a technical tutorial by the tool's creator, demonstrating real-world attack techniques with practical examples. The information is accurate and detailed, but lacks formal citations and peer review.

Key Moments

Cited Sources

  • GraphSpy GitHub Repository — The main tool being demonstrated, with source code and documentation.
  • Keanu's GitHub — The developer's GitHub profile, containing other projects.
  • Keanu's LinkedIn — The developer's professional profile.

Concurring Sources

External References

Contribution & Novelties

The video provides an in-depth look at GraphSpy, a relatively new tool that simplifies complex Azure AD attack techniques. It showcases novel approaches to persistence, such as adding a FIDO2 key to a victim’s account, which is not widely documented. The tool itself is open-source, contributing to the offensive security community.

Pour aller plus loin :

105 words

Radar Profile

The radar profile shows high scores in technical level and information quality, indicating a deeply technical and informative video. The lower score in information quantity suggests that while the content is rich, it may not cover a broad range of topics. Overall, the video is a strong resource for advanced cybersecurity practitioners.

Reliability 8/10

💬 Sur les 0 commentaires analysés, aucune tendance n'est disponible.