Skip to content
OPS // KITitspentest.sh

PE-TOK

TokenTacticsV2

PowerShell toolkit for manipulating and refreshing Entra ID access/refresh tokens across Microsoft resource scopes, with CAE and v2 endpoint support.

Official siteBack to catalog

OVERVIEW

TokenTacticsV2 (f-bader/TokenTacticsV2) is a PowerShell module maintained by Fabian Bader as an actively updated fork of the original TokenTactics by Stephan Borosh (@rvrsh3ll) and Bobby Cooke (@0xBoku), adding support for Continuous Access Evaluation (CAE) tokens and the v2 token endpoint that the original project didn't cover. It lets a tester obtain an Entra ID refresh token — typically via the device-code phishing flow — and then refresh it toward FOCI-capable resources such as Microsoft Graph, Outlook/Substrate, SharePoint, or Teams.

Because a FOCI refresh token issued to one Microsoft first-party client can be redeemed for access tokens to many other first-party apps, TokenTacticsV2 is used to demonstrate what an attacker can reach after a single successful device-code phish or token theft — reading mail via `Invoke-RefreshToSubstrateToken`, dumping tenant data via a Graph token, or reaching Teams and SharePoint, without ever touching the user's password.

USE CASES

Practical use cases

  • 01

    Converting a phished or obtained device-code refresh token into access tokens for Outlook, SharePoint, Teams, and Microsoft Graph.

  • 02

    Demonstrating the real reach of a single obtained FOCI refresh token across a tenant's Microsoft 365 resources.

  • 03

    Testing whether Continuous Access Evaluation and conditional access actually constrain a pivoted token's lifetime and scope.

  • 04

    Building a device-code phishing simulation to show a client how a fake sign-in prompt leads to persistent mailbox/file access.

QUICK START

Once post-exploitation testing with an obtained Entra ID token or device-code flow is authorized, to refresh and pivot that token across Microsoft resource scopes (Graph, Outlook, SharePoint, Teams).

  1. Import the module once a phishing-simulation or token-testing engagement is scoped and authorized: `Import-Module .\TokenTactics.psd1`.
  2. Obtain an initial refresh token, most commonly via the built-in device-code flow: `Get-EntraIDTokenFromDeviceCode -Client MSGraph`.
  3. Send the resulting code/URL only to the specific test users agreed with the client, never to arbitrary tenant members.
  4. Use the saved `$response` refresh token with functions like `Invoke-RefreshToSubstrateToken` or `Invoke-RefreshToMSGraphToken` to pivot to other resources, and log each pivot for the report.
Import-Module — bash
Import-Module .\TokenTactics.psd1; Get-EntraIDTokenFromDeviceCode -Client MSGraph

BEFORE YOU RUN IT

What to check before running it

The device-code flow this tool relies on is itself a phishing technique against real end users — it must be explicitly authorized in writing and scoped to named test users before any code/URL is sent, not just approved at the infrastructure level.

Every token refresh and resource pivot is a real Entra ID sign-in/token event visible in the sign-in logs and, where enabled, Continuous Access Evaluation telemetry — document expected activity for the blue-team debrief.

Refresh tokens obtained this way remain valid until revoked or expired; agree with the client on a hard stop and revoke test tokens (e.g. via the Entra portal or AADInternals) once the engagement ends.

KEEP EXPLORING

View the whole phase →