-
Notifications
You must be signed in to change notification settings - Fork 43
OAuthPermissions‐Analyzer
evild3ad edited this page Apr 27, 2024
·
3 revisions
OAuthPermissions-Analyzer.ps1 is a PowerShell script utilized to simplify the analysis of M365 OAuth Permissions extracted via Microsoft-Extractor-Suite by Invictus-IR.
Fig 1: OAuthPermissions-Analyzer
Fig 2: Application Permissions
Fig 3: Delegated Permissions → eM Client (Traitorware)
Fig 4: ClientDisplayName / AppId (Stats)
Fig 5: PermissionType / Permission (Stats)
Fig 6: PublisherName / ClientDisplayName (Stats)
Fig 7: Statistics
M365_Oauth_Apps - Repository of suspicious Enterprise Applications (BEC)
Microsoft Graph permissions reference
App consent grant investigation