Illicit Consent Grant phishing
1) Create an Application
2) Create Client Secret
3) Add API Permissions
4) Check User Consent Permissions
Import-Module AzureADPreview.psd15) Setup the 365-Stealer
6) Start the 365-Stealer
7) Get the Phishing Link
8) Enumerate Applications for Phishing
9) Get the Access Tokens
10) Get Admin Consent
11) Abuse the Access Token
12) Refresh All Tokens
Last updated