Ross ROSS = Recommend OSS · open-source software intelligence for agents

RedByte1337/GraphSpy

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI observed · 2026-08-28

github.com/RedByte1337/GraphSpy · HTML · BSD-3-Clause (permissive) observed · 2026-08-28

Health v2 · maintenance only

70/100

  • Activity 99
  • Release rhythm 35
  • Longevity 67

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 938
  • days_rel: n/a
  • days_push: 7
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1386 stars · 184 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

GraphSpy is an initial access and post-exploitation tool for Microsoft Entra ID (Azure AD) and Microsoft 365, offering a browser-based GUI served locally. It is installed via pipx and helps security professionals interact with Microsoft Graph and related APIs during authorized penetration tests.

Use cases

  • explore entra id tenants during a pentest
  • post-exploitation of microsoft 365 accounts
  • query microsoft graph api with a gui
  • dump emails and files from compromised m365 accounts
  • enumerate users and permissions in azure ad
  • red team tooling for cloud environments

When to choose

  • you are doing authorized red team or pentest work against Entra ID/M365
  • you want a browser GUI instead of raw Graph API calls
  • you need a cross-platform Python tool installable via pipx

When to avoid

  • you need a defensive or monitoring tool rather than offensive testing
  • you lack authorization to test the target tenant
  • you need automated large-scale scanning rather than interactive exploration

Facets

application · maturity active

security gui http-client security penetration-testing python cross-platform windows entra-id microsoft-365 red-team post-exploitation initial-access offensive-security browser-based-gui linux web-server

1 source

Member repositories

RepositoryRoleHealth v2
RedByte1337/GraphSpymain70

For agents

markdown · JSON · MCP: product_card(name="RedByte1337/GraphSpy")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem