RedByte1337 Profile Banner
Keanu Nys Profile
Keanu Nys

@RedByte1337

Followers
825
Following
127
Media
15
Statuses
86

Offensive Security Lead @ Spotit. Creator of GraphSpy

Belgium
Joined August 2014
Don't wanna be here? Send us removal request.
@RedByte1337
Keanu Nys
1 year
๐Ÿš€I'm finally releasing GraphSpy to the public!๐Ÿ•ต๏ธ.A powerful offensive security tool focused on making initial access and post-compromise enumeration in Microsoft Entra and M365 much more convenient during penetration tests and red team assessments!.
Tweet card summary image
github.com
Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI - RedByte1337/GraphSpy
2
135
366
@RedByte1337
Keanu Nys
5 days
I will be sharing more in-depth details and the tools/scripts I created to set up some of these attacks in a blog post very soon!.
0
0
17
@RedByte1337
Keanu Nys
5 days
Thanks to everyone who joined my DEFCON33 talk!๐ŸŽ‰.For those of you who missed it and are interested in seeing how we can extract cleartext credentials and bypass MFA directly from the official Microsoft login page, I just uploaded the recording to YouTube:.
Tweet media one
14
141
520
@RedByte1337
Keanu Nys
9 days
RT @Wietze: A special shoutout to the many ๐Ÿ‡ช๐Ÿ‡บEuropean cyber researchers presenting their work at #DEFCON, you were awesome. ๐Ÿ‡ณ๐Ÿ‡ฑ@_dirkjan @Jโ€ฆ.
0
5
0
@RedByte1337
Keanu Nys
1 month
I just noticed that the domain enumeration technique with the Autodiscover endpoint is suddenly not working anymore. This is what tools like @DrAzureAD's AADInternals (Get-AADIntTenantDomains) used to allow unauthenticated enumeration of all domains linked to an Entra ID tenant.
Tweet media one
Tweet media two
6
17
86
@RedByte1337
Keanu Nys
2 months
RT @nikhil_mitt: Grab a seat for one of @AlteredSecurity's three popular Red Team classes at @BlackHatEvents . Azure Attacks Advanced (In-โ€ฆ.
0
5
0
@RedByte1337
Keanu Nys
2 months
I am very excited to share that Iโ€™ve been accepted to speak on one of the main stage tracks at @defcon this August in Las Vegas! ๐ŸŽ‰. Can't wait to share this research on one of the biggest stages in the hacking community! ๐Ÿ”ฅ. Let me know if youโ€™ll be at #DEFCON33!. #DEFCON
Tweet media one
3
5
43
@RedByte1337
Keanu Nys
2 months
โค๏ธโ€๐Ÿ”ฅ If you want to support the development of GraphSpy and get early access to new features, check out the ๐ฌ๐ฉ๐จ๐ง๐ฌ๐จ๐ซ ๐ฉ๐š๐ ๐ž here: Thanks to @infosecnoodle and @q8fawazo for already supporting GraphSpy before this public announcement. โค๏ธ.
0
0
5
@RedByte1337
Keanu Nys
2 months
โš’๏ธ ๐‘ช๐’“๐’๐’”๐’” ๐’•๐’๐’๐’ ๐’”๐’–๐’‘๐’‘๐’๐’“๐’• โ€” Import/Export device certificates, Primary Refresh Tokens, and WinHello keys to easily switch between your favorite tools (e.g. roadtools, AADInternals, pytune, . ) while keeping track of all your certificates/tokens/keys in GraphSpy.
1
0
2
@grok
Grok
2 days
Join millions who have switched to Grok.
23
24
198
@RedByte1337
Keanu Nys
2 months
๐Ÿช ๐‘ท๐‘น๐‘ป ๐‘ช๐’๐’๐’Œ๐’Š๐’†๐’” โ€” Generate ๐๐‘๐“ ๐‚๐จ๐จ๐ค๐ข๐ž๐ฌ using the Primary Refresh Tokens in GraphSpy, allowing signing in to ๐š๐ง๐ฒ ๐ฐ๐ž๐›๐ฌ๐ข๐ญ๐ž ๐ฎ๐ฌ๐ข๐ง๐  ๐„๐ง๐ญ๐ซ๐š ๐ˆ๐ƒ ๐š๐ฎ๐ญ๐ก๐ž๐ง๐ญ๐ข๐œ๐š๐ญ๐ข๐จ๐ง, without needing the ๐ฎ๐ฌ๐ž๐ซ'๐ฌ ๐ฉ๐š๐ฌ๐ฌ๐ฐ๐จ๐ซ๐ ๐จ๐ซ ๐Œ๐…๐€!.
1
0
0
@RedByte1337
Keanu Nys
2 months
๐Ÿ–ฅ๏ธ ๐‘จ๐’–๐’•๐’๐’Ž๐’‚๐’•๐’†๐’… ๐’‘๐’๐’”๐’•-๐’„๐’๐’Ž๐’‘๐’“๐’๐’Ž๐’Š๐’”๐’† ๐’‚๐’„๐’•๐’Š๐’๐’๐’” โ€” New ๐š๐ฎ๐ญ๐จ๐ฆ๐š๐ญ๐ข๐œ ๐š๐œ๐ญ๐ข๐จ๐ง๐ฌ can be configured to set up persistence within 5 seconds (e.g. ๐ซ๐ž๐ ๐ข๐ฌ๐ญ๐ž๐ซ๐ข๐ง๐ /๐ฃ๐จ๐ข๐ง๐ข๐ง๐  ๐š ๐๐ž๐ฏ๐ข๐œ๐ž, requesting a ๐๐‘๐“, ๐ž๐ง๐ซ๐จ๐ฅ๐ฅ๐ข๐ง๐  WinHello).
1
0
0
@RedByte1337
Keanu Nys
2 months
๐Ÿค– ๐‘จ๐’–๐’•๐’๐’Ž๐’‚๐’•๐’†๐’… ๐’…๐’†๐’—๐’Š๐’„๐’† ๐’„๐’๐’…๐’† ๐’†๐’๐’•๐’“๐’š โ€” Skip the first step where the victim needs to fill in the code. GraphSpy ๐ ๐ž๐ง๐ž๐ซ๐š๐ญ๐ž๐ฌ ๐ญ๐ก๐ž ๐๐ž๐ฏ๐ข๐œ๐ž ๐œ๐จ๐๐ž ad-hoc, fills it in on the legit devicelogin page, and redirects the user to complete the flow.
1
0
1
@RedByte1337
Keanu Nys
2 months
GraphSpy just got scarily powerful!๐Ÿ”ฅ. ๐Ÿค–Automated device code entry.๐Ÿ–ฅ๏ธPost-comprimise automation (device registration, WinHelloForBusiness, . ).๐ŸชPRT Cookies.โš’๏ธCross-tool support. โค๏ธโ€๐Ÿ”ฅThe sponsor branch is now live for early access: ๐ŸงตMore info below
1
32
103
@RedByte1337
Keanu Nys
4 months
๐Ÿ“ง GraphSpy 1.5.0 is out now and brings a brand new Outlook Graph module!. โœ…Read emails in any folder.โœ…Send HTML-formatted emails directly in GraphSpy.โœ…Access shared mailboxes.โœ…Search for sensitive information like passwords. ๐Ÿ”—Check out GraphSpy here:.
Tweet media one
Tweet media two
1
24
62
@RedByte1337
Keanu Nys
4 months
Microsoft seems to have recently deprecated the legacy account.activedirectory.windowsazure[.]com endpoint, which GraphSpy was using to list and add MFA methods for a user. GraphSpy 1.4.3 now utilizes the mysignins[.]microsoft[.]com API now (which is also a FOCI resource!)
Tweet media one
Tweet media two
0
4
18
@RedByte1337
Keanu Nys
7 months
RT @merill: I just published this week's Entra newsletter!. Featuring @12Knocksinna, @alitajran, @Christian_Frohn, @Ciraltos, @DanielatOCN,โ€ฆ.
0
12
0
@RedByte1337
Keanu Nys
7 months
GraphSpy just hit 600 stars on GitHub after releasing version 1.4!โœจ. This version introduces the new Entra ID module, better loading animations, and JSON syntax highlighting. Check it out here: .
Tweet media one
Tweet media two
Tweet media three
3
24
67
@RedByte1337
Keanu Nys
9 months
RT @mrgretzky: Defenders use cross-origin requests through CSS url() or injected JS to leak your phishing URL in the HTTP Referer header.โ€ฆ.
0
35
0
@RedByte1337
Keanu Nys
11 months
Last week to register in the Azure Red Team Expert bootcamp from @AlteredSecurity!.Join me during the 4 live sessions in October to level up your Azure Red Teaming skills.
Tweet card summary image
alteredsecurity.com
This 2-week advanced bootcamp is designed to help security professionals in taking their Azure Red Team skills to the next level.
0
1
3