Skip to content
OPS // KITitspentest.sh

X-AZU

azure_oauth_phishing_example

Minimal reference implementation of an Entra ID OAuth consent-phishing page, used to demonstrate illicit-consent-grant impact in authorized engagements.

Official siteBack to catalog

OVERVIEW

azure_oauth_phishing_example (carlospolop/azure_oauth_phishing_example) is a small, unlicensed reference script — published alongside the author's HackTricks Cloud documentation on Entra ID OAuth app phishing — that walks through the minimum needed to run an illicit-consent-grant attack: register an Entra ID application, request a set of Microsoft Graph permissions (e.g. `Mail.Read`, `Files.ReadWrite.All`, `User.Read`), and stand up a local page that redirects a victim through the real Microsoft consent prompt back to a `/callback` endpoint that captures the authorization code.

It exists as teaching/reference code rather than a maintained product, which makes it useful for explaining the mechanics of the technique clearly: the victim never gives up a password, they only click 'Accept' on a consent screen for an application that looks legitimate, and Entra ID itself hands the attacker's redirect URI a code that is exchanged for an access/refresh token scoped to whatever permissions were requested and consented to.

USE CASES

Practical use cases

  • 01

    Building a minimal, self-hosted proof-of-concept consent page to demonstrate illicit-consent-grant phishing to a client during a scoped simulation.

  • 02

    Explaining, with working code, why consent phishing bypasses password-based MFA controls entirely.

  • 03

    Walking a client's security team through exactly which Microsoft Graph scopes an attacker-controlled app would need to read mail, files, or profile data.

  • 04

    Pairing with a fuller tool like 365-Stealer once the client wants an automated, reporting-capable version of the same technique.

QUICK START

Once a consent-phishing simulation against Entra ID users is explicitly authorized and scoped with the client, as a minimal reference for hosting the OAuth consent page and redeeming the resulting code.

  1. Get the consent-phishing simulation, including the exact scopes and target users, explicitly authorized and scoped in writing before registering anything.
  2. Register a throwaway Entra ID application, create a client secret, and set the redirect URI to the callback endpoint you control (default `http://localhost:8000/callback`).
  3. Select only the Graph permissions agreed with the client for the simulation (e.g. `Mail.Read`, `Files.ReadWrite.All`, `User.Read`).
  4. Run the script and send the resulting consent URL only to the pre-agreed test recipients: `python3 azure_oauth_phishing_example.py --client-secret <secret> --client-id <id> --scopes 'email,Mail.Read,User.Read,offline_access,openid,profile'`.
  5. Use the captured access token strictly to demonstrate impact to the client, then revoke the app's consent and delete the captured token/secret.
python3 — bash
python3 azure_oauth_phishing_example.py --client-secret <client-secret> --client-id <client-id> --scopes 'email,Mail.Read,User.Read,offline_access,openid,profile'

BEFORE YOU RUN IT

What to check before running it

This is example/reference code with no license file and no maintenance guarantees — read it fully before running it, and treat it as a teaching aid rather than a production phishing tool.

Consent phishing targets real end users' judgment, not infrastructure — it requires explicit written authorization naming the target users, the exact scopes requested, and the simulation window, separate from any technical-only pentest authorization.

A successful consent grant shows up in Entra ID as an OAuth application consent event and subsequent Graph API sign-ins from the attacker's app — agree with the client on what should appear in the audit/sign-in logs so the blue team can validate their detection during the debrief.

KEEP EXPLORING

View the whole phase →