Ross ROSS = Recommend OSS · open-source software intelligence for agents

dafthack/GraphRunner

A Post-exploitation Toolset for Interacting with the Microsoft Graph API observed · 2026-08-28

github.com/dafthack/GraphRunner · PowerShell · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

62/100

  • Activity 76
  • Release rhythm 35
  • Longevity 79

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1114
  • days_rel: n/a
  • days_push: 146
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1333 stars · 169 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

GraphRunner is a post-exploitation toolset for interacting with the Microsoft Graph API, written in PowerShell. It enables reconnaissance, persistence, and data pillaging against Microsoft Entra ID (Azure AD) accounts using authenticated access tokens.

Use cases

  • search and export a compromised user's email, OneDrive, and SharePoint files
  • dump Teams chats and channels from an account with a stolen token
  • enumerate app registrations and conditional access policies in a tenant
  • find modifiable security groups and misconfigured mailboxes during red team engagements
  • harvest OAuth authorization codes during consent grant attacks
  • maintain persistence by refreshing token packages and deploying malicious apps

When to choose

  • you are doing authorized post-exploitation or red team work against Microsoft 365 / Entra ID
  • you need a dependency-free PowerShell toolset that works on Windows and Linux
  • you want both a CLI and an HTML GUI for pillaging an account via Graph API tokens

When to avoid

  • you need a defensive auditing or compliance tool rather than offensive tradecraft
  • your target is not Microsoft Graph / Entra ID
  • you require stealth features or C2 integration beyond token-based Graph interaction

Facets

cli-tool · maturity active

security http-client cli security penetration-testing windows cli post-exploitation microsoft-graph azure-ad entra-id red-team offensive-security oauth reconnaissance powershell linux

1 source

Member repositories

RepositoryRoleHealth v2
dafthack/GraphRunnermain62

For agents

markdown · JSON · MCP: product_card(name="dafthack/GraphRunner")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem