Executing Device Code Phishing Attacks
Course Content
0 / 45 completedIntroduction
Kickstarting Your Pentesting Lab with FREE Microsoft 365 in Azure
Secure Your Admin Pentesting Account
Activate Free Azure Subscription with 200$ FREE Credit
Setting Up Entra ID User Accounts for Effective Pentesting
Domain Name Discovery Methods and Tools
Essential Methods for Getting Domains
Introduction to AAD Internals
Accessing OpenID Information Made Simple
Microsoft Entra ID Explained
Understanding Naming Convention Essentials
Exploring User Enumeration as an Outsider
Reconnaissance of Azure from an Outsider's Perspective
Conducting User Enumeration on Multiple Accounts from Outside
Microsoft Entra ID Roles and Azure Permissions Explained
Password Spray Attacks Explained
Understanding Brute Force Attack Technique
Understanding the Prerequisites for Phishing Lab
Introduction to Phishing Framework to Bypass MFA
Setting Up Infrastructure for EvilGinx
Setting Up MFA Before Phishing Attempt
Device Code Phishing Techniques
Executing Phishing Attacks Using EvilGinx
Evilginx Installation Guide for Pentesters
Step-by-Step Guide Performing a Password Spray Attack
Understanding GraphSpy Overview and Application
Introduction to Storage Hunting
GraphSpy Installation and Configuration
Creating Pentesting Lab for Blob Hunting
Executing Device Code Phishing Attacks
Cloud Storage Account Explained
Setting up Pentesting Tool to Exploit Blob Storage
Predictable Resource Location Attack with FeroxBuster
How to Exploit Cloud Storage Account
Other Tools for Blob Hunting
Initial Access Threat Protection
Strengthening Your Security Against Brute Force Attacks
Password Spray Attack Prevention
Protection against EvilGinx
Advantage of Identity Protection
Techniques and Tools to Prevent Phishing Attack
Conditional Access Policies Explained
Device Code Abuse Protection
Protection Against Blob Hunting
Implementation of Conditional Access