X-365
365-Stealer
Automates the Entra ID illicit-consent-grant attack end to end — malicious app registration, phishing page, and post-consent data exfiltration.
OVERVIEW
365-Stealer (AlteredSecurity/365-Stealer) is a Python3 tool, with an optional PHP-based management portal, that automates the entire illicit-consent-grant attack chain against Entra ID: `--app-registration` scripts the malicious Azure app registration and lets the operator choose client-secret or device-code authentication and default/LowImpact/custom permission sets, `--run-app` hosts the phishing consent page, and once a victim clicks Accept, the tool captures their refresh token and stores it for reuse.
Beyond the initial consent theft, it automates what a red team would otherwise do manually to show impact: requesting new access tokens for compromised users on demand, dumping mail, OneDrive files, and OneNote content into its management database, sending mail or creating malicious Outlook forwarding rules on the victim's behalf, and even backdooring a `.docx` stored in the victim's OneDrive. A `--custom-steal` flag and configurable delay let an operator scope exactly what is exfiltrated and how aggressively, which matters for staying inside a signed rules-of-engagement document.
USE CASES
Practical use cases
- 01
Running an end-to-end illicit-consent-grant phishing simulation, from malicious app registration through post-consent data access, to show a client concrete business impact.
- 02
Demonstrating that a captured refresh token gives an attacker mail, OneDrive, and OneNote access for an extended period without ever needing the victim's password.
- 03
Showing how a compromised consent grant can be escalated into further compromise, e.g. malicious Outlook forwarding rules or a backdoored OneDrive document.
- 04
Testing whether a tenant's admin-consent workflow and app-permission review actually catch a request for high-impact Graph scopes.
QUICK START
Once an illicit-consent-grant phishing simulation against a client's Entra ID tenant is explicitly authorized and scoped, to automate app registration, the consent phish, and post-consent data access.
- Get the simulation — target users, permission scopes, exfiltration actions, and time window — explicitly authorized and scoped in writing before registering any app.
- Clone the repo and install dependencies: `git clone https://github.com/AlteredSecurity/365-Stealer.git && cd 365-Stealer && pip install -r requirements.txt`.
- Register the phishing application, either automated or manually in the Azure portal: `python 365-Stealer.py --app-registration`.
- Host the consent page with `--run-app` and send the resulting consent link only to the pre-approved test recipients.
- Use `--custom-steal` and the delay option to limit exactly what is pulled from consenting accounts, matching what the client authorized.
python 365-Stealer.py --app-registrationBEFORE YOU RUN IT
What to check before running it
This tool directly targets real end users' judgment and their mailbox/file data — it requires explicit written authorization naming the target users, the exact permissions requested, and the data the simulation is allowed to touch, separate from any infrastructure-only pentest scope.
Actions like sending mail as the victim, creating Outlook forwarding rules, or backdooring OneDrive files are destructive/persistent — get specific client sign-off before enabling any of them, and remove them before closing the engagement.
A successful run leaves an OAuth app-consent event and subsequent Graph API activity from that app in Entra ID's audit and sign-in logs — document exactly what should appear there so the blue team can validate detection during the debrief.