Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
GraphSpy — Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI | Kitploit
Tools/GitHubGitHub/redbyte1337/graphspy
Phishing ToolsPersistence MechanismsData ExfiltrationInformation GatheringPost-ExploitationPenetration TestingCloud SecurityAuthenticationRed Teaming
GitHubredbyte1337/graphspy

GraphSpy

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

1.4k179271 month agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

PyPi Version Python Version GitHub Sponsors Twitter LinkedIn

GraphSpy

   ________                             _________
  /       /  by RedByte1337    __      /        /           
 /  _____/___________  ______ |  |__  /   _____/_____ ______
/   \  __\_  __ \__  \ \____ \|  |  \ \_____  \\____ \   |  |
\    \_\  \  | \/  __ \|  |_> |   \  \/        \  |_> \___  |
 \______  /__|  |____  |   __/|___|  /_______  /   ___/ ____|
        \/           \/|__|        \/        \/|__|   \/

Table of Contents

  • GraphSpy
  • Table of Contents
  • Quick Start
    • Installation
    • Execution
    • Usage
  • Features
  • Release Notes
  • Upcoming Features
  • Sponsors
  • Credits

Quick Start

Installation

The following goes over the recommended installation process using pipx to avoid any dependency conflicts.

GraphSpy is built to work on every operating system, although it was mainly tested on Linux and Windows.

For other installation options and detailed instructions, check the Installation page on the wiki.

# Install pipx (skip this if you already have it)
apt install pipx
pipx ensurepath

# Install the latest version of GraphSpy from pypi
pipx install graphspy

Execution

After installation, the application can be launched using the graphspy command from any location on the system.

Running GraphSpy without any command line arguments will launch GraphSpy and make it available at http://127.0.0.1:5000 by default.

graphspy

Now simply open http://127.0.0.1:5000 in your favorite browser to get started!

Use the -i and -p arguments to modify the interface and port to listen on.

# Run GraphSpy on http://192.168.0.10
graphspy -i 192.168.0.10 -p 80
# Run GraphSpy on port 8080 on all interfaces
graphspy -i 0.0.0.0 -p 8080

For detailed instructions and other command line arguments, please refer to the Execution page on the wiki.

Usage

Please refer to the GitHub Wiki for full usage details.

For a quick feature overview, check out the official release blog post.

Development

If you are contributing to GraphSpy or modifying internals, start here:

  • DEVELOPMENT.md - architecture, request lifecycle, schema model, and extension rules
  • AI_POLICY.md - Important: Read the policy describing acceptable use of AI for this project if you have any intention of using AI
  • AI.md - canonical coding and review guardrails for humans and coding agents

Features

Access and Refresh Tokens

Store your access and refresh tokens for multiple users and scopes in one location.

Access Tokens

Refresh Tokens

Easily switch between them or request new access tokens from any page.

Token Side Bar

Device Codes

Easily create and poll multiple device codes at once. If a user used the device code to authenticate, GraphSpy will automatically store the access and refresh token in its database.

Device Codes

Configure automatic actions to take place instantly after a successful device code authentication.

  1. Device PRT: Register/join a new device to Entra ID, obtain the device certificate, and use it to generate a Primary Refresh Token (PRT)
  2. Winhello: Everything in Device PRT + try to enroll the fake device with Windows Hello For Business (whfb) to obtain WinHello keys.
  3. More to come later...

Device Code Winhello Action

MFA Methods

View, modify and create MFA methods linked to the account of the user.

MFA Methods Overview

The following MFA methods can be added from GraphSpy to set up persistance:

  • Microsoft Authenticator App
  • Custom OTP App, or use GraphSpy as OTP app to generate TOTP codes on the fly!
  • FIDO Security Keys!
  • Alternative email address
  • Mobile/Office/Alternative Phones (SMS or call)

MFA Methods FIDO

Primary Refresh Tokens (PRTs)

Request, import or use primary refresh tokens from within GraphSpy.

These PRTs are a lot more powerful than regular refresh tokens, since these are not bound to one specific application, but can instead be used to obtain access tokens for ANY application/scope as the user (both FOCI and non-FOCI ones).

PRT Overview

Additionally, these PRT tokens can be used to generate PRT Cookies, which can be imported directly in a browser to provide a full interactive access to any web application integrated with Entra ID SSO.

PRT Cookies

Windows Hello For Business

Register Windows Hello For Business (whfb) keys in GraphSpy for a user & device combination, or import them from a different tool or a compromised device.

These WinHello keys can be used to generate new Primary Refresh Tokens for the user, even after password password resets, making them very powerful account persistence!

Winhello Keys

Files and SharePoint

Browse through files and folders in the user's OneDrive or any accessible SharePoint site through an intuitive file explorer interface.

Of course, files can also be directly downloaded, or new files can be uploaded.

OneDrive

Additionally, list the user's recently accessed files or files shared with the user.

Recent Files

Outlook

Open the user's Outlook web mail with a single click using just an Outlook access token (FOCI)!

Download Tool