LogoClawIndex
CasesSkillsAbout
LogoClawIndex

attacking-oauth-with-device-code-phishing - Assess OAuth device-code phishing in Entra ID

Conduct authorized testing of OAuth device-code and illicit-consent phishing against Microsoft Entra ID and assess token theft, MFA bypass, and cloud access risks.

Tags

Updated: 2026-09-29
device-code-phishingoauthentra-idtoken-theftmfa-bypassillicit-consentred-teamidentity-access-management

Capabilities

Initiate device-code requestsDeliver authorized phishing pretextsPoll token endpointsCapture OAuth tokens

Typical Inputs

Written authorization and rules of engagementTarget Entra ID tenantSanctioned delivery channel

Typical Outputs

Device-code request responsesOAuth access and refresh tokensMicrosoft 365 resource access

What this skill does

  • Initiate device-code requests
  • Deliver authorized phishing pretexts
  • Poll token endpoints
  • Capture OAuth tokens
  • Refresh Microsoft 365 tokens
  • Test illicit consent grants
  • Enumerate accessible resources
  • Document findings and remediation

Inputs

  • Written authorization and rules of engagement
  • Target Entra ID tenant
  • Sanctioned delivery channel
  • Attacker host
  • TokenTactics installation
  • ROADtools installation
  • OAuth client and scope configuration

Outputs

  • Device-code request responses
  • OAuth access and refresh tokens
  • Microsoft 365 resource access
  • Resource enumeration results
  • Assessment findings and remediation recommendations

Requirements

  • Authorized security-testing scope
  • Linux or Windows host
  • Python 3.8 or later
  • PowerShell 7 or later
  • TokenTactics
  • ROADtools

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.