Agent skill

Hunt M365

by Encod3d-Sec in Encod3d-Sec/TORCH

Microsoft 365 / Entra ID attack - tenant discovery, user enumeration via OneDrive differential (2026 verified), AADSTS code reference, Smart Lockout math (hard cap 1-2 attempts/user), ROPC…

MITAuto-check passedDocuments & Office

Install Hunt M365

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill hunt-m365 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH hunt-m365 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt/hunt-m365 .claude/skills/hunt-m365 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-m365
GitHub stars
329
Token cost
~2k tokens
SKILL.md length
737 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Microsoft 365 / Entra ID attack - tenant discovery, user enumeration via OneDrive differential (2026 verified), AADSTS code reference, Smart Lockout math (hard cap 1-2 attempts/user), ROPC…

  • Works in 3 steps: Tenant discovery - zero auth, zero… → User enumeration via OneDrive… → Auth (ROPC) - LAST, and hard-capped.…
  • Tasks that involve Cloud office suites
  • SKILL.md covers Wiki, Attack surface (ranked - spend…, AADSTS Code Reference (Memorize) and Smart Lockout Math (Hard Cap…, plus 7 more sections
  • Calls python3 and curl; reaches graph.windows.net and login.microsoftonline.com; needs VALID_TOKEN

What it does

Hunt M365 is an agent skill from Encod3d-Sec/TORCH. Microsoft 365 / Entra ID attack - tenant discovery, user enumeration via OneDrive differential (2026 verified), AADSTS code reference, Smart Lockout math (hard cap 1-2 attempts/user), ROPC validation, Conditional Access mapping. Wiki-first, FIND schema output.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Documents & Office, covering Cloud office suites. It works with Microsoft 365, Microsoft Entra ID and Microsoft OneDrive. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.

When your agent uses it

  • Tasks that involve Cloud office suites

Example prompts

  • “/hunt-m365”

Requirements

  • Python 3
  • A credential in VALID_TOKEN

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Tenant discovery - zero auth, zero lockout. Namespace type, tenant ID, SharePoint presence.
  2. User enumeration via OneDrive differential - zero auth, zero lockout. Build the full user list here; it costs nothing against the lockout…
  3. Auth (ROPC) - LAST, and hard-capped. Only after 1 and 2 are done. This is the ONLY step that burns the Smart Lockout budget: at most 1-2…

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • graph.windows.net
    • login.microsoftonline.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • VALID_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hunt M365 loads about 2k tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 737 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 737 words, ~2,006 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-m365/SKILL.md (or your agent's skills folder).
name
hunt-m365
description
Microsoft 365 / Entra ID attack - tenant discovery, user enumeration via OneDrive differential (2026 verified), AADSTS code reference, Smart Lockout math (hard cap 1-2 attempts/user), ROPC validation, Conditional Access mapping. Wiki-first, FIND schema output.

Hunt: M365 / Entra ID

Assumes hunt-core for the scope gate, two-account rule, confirmation gate, enumeration limits, stop conditions, wiki protocol, FIND output, and Deadends. Do not re-derive any of that here.

Wiki

qmd_query "Microsoft 365 Entra ID Azure AD tenant discovery user enumeration OneDrive AADSTS smart lockout conditional access ROPC" via wiki-search MCP

Hub: [[cloud-moc]] (live index). Primary page: [[azure-ad-enumerate]]. Anchors: [[azure-ad-conditional-access-policy]] (the CA gap you must prove bypassed), [[azure-ad-access-and-tokens]] (ROPC / token issuance).

Attack surface (ranked - spend the zero-auth signal before any auth attempt)

Fingerprint (target is M365/Entra) when you see: *.onmicrosoft.com, *-my.sharepoint.com, login.microsoftonline.com redirects, enterpriseregistration.* records, or "Microsoft 365" in tech-stack notes.

  1. Tenant discovery - zero auth, zero lockout. Namespace type, tenant ID, SharePoint presence.
  2. User enumeration via OneDrive differential - zero auth, zero lockout. Build the full user list here; it costs nothing against the lockout counter, so do it exhaustively before touching auth.
  3. Auth (ROPC) - LAST, and hard-capped. Only after 1 and 2 are done. This is the ONLY step that burns the Smart Lockout budget: at most 1-2 attempts per user, ever. See the math below; the ROPC helper enforces it.

AADSTS Code Reference (Memorize)

CodeMeaningLockout hit?Action
50034User does not existNOSkip - remove from spray list
50126Wrong passwordYES (+1)User exists - try alternate later
50053Account locked (Smart Lockout)n/aPre-existing lockout - flag to client; do NOT retry
53003CA blocked token issuanceYES (+1)PASSWORD VALID
50076MFA requiredYES (+1)PASSWORD VALID
50079Strong auth requiredYES (+1)PASSWORD VALID
50158External auth requiredYES (+1)PASSWORD VALID
530003Device-state requiredYES (+1)PASSWORD VALID

Codes {53003, 50076, 50079, 50158, 530003} = password confirmed valid. Microsoft only returns these AFTER credential validation.

Smart Lockout Math (Hard Cap Discipline)

  • Default: 10 failed attempts in 10 min -> lockout
  • Counter shared across ALL flows (ROPC + SAML + IMAP + EWS)
  • Hard cap: <=1-2 password attempts per user per engagement
  • With 1 attempt/user, lockout is mathematically impossible
  • Any AADSTS50053 = pre-existing lockout from another actor

This cap is stricter than the hunt-core generic enumeration ceiling and overrides it. Never batch a password list against a user, never loop the ROPC helper without its per-email attempt file, and never re-run a user that already spent its attempt. If a step would exceed 1-2 attempts/user, stop and reduce it.

Tenant Discovery

bash
msftrecon -d client.example
# Key fields: Tenant ID, Namespace Type (Managed = ROPC works | Federated = ADFS)
# SharePoint Detected: Yes -> OneDrive enum available

User Enumeration (OneDrive Differential - Verified May 2026)

bash
# 200 with ~57KB body = user EXISTS (licensed)
# 404 with 0 bytes = user DOES NOT EXIST
curl -sk "https://<tenant>-my.sharepoint.com/personal/<user>_<domain>_com/_layouts/15/onedrive.aspx"

# Zero auth attempts -- zero lockout impact

Signal: OneDrive 404 + ROPC AADSTS50126 = functional/shared mailbox account (no OneDrive license, has password) = prime target for spray (historically MFA-exempt).

ROPC Validation (Single-Attempt Pattern)

HARD_CAP = 1 is load-bearing, not a default. The per-email attempt file is what keeps step 3 inside the Smart Lockout math above - do not remove it, do not raise the cap, do not call attempt() in a bare list loop.

python
import urllib.request, urllib.parse, ssl, json, os

HARD_CAP = 1  # Never higher
ATTEMPT_FILE = "engagement_log/o365_attempts.json"

def attempt(email, password):
    state = json.load(open(ATTEMPT_FILE)) if os.path.exists(ATTEMPT_FILE) else {}
    if state.get(email.lower(), 0) >= HARD_CAP:
        return {"status": "SKIPPED_CAP"}
    
    ctx = ssl.create_default_context()
    ctx.check_hostname = False
    ctx.verify_mode = ssl.CERT_NONE
    
    body = urllib.parse.urlencode({
        "resource": "https://graph.windows.net",
        "client_id": "1b730954-1685-4b74-9bfd-dac224a7b894",
        "client_info": "1",
        "grant_type": "password",
        "username": email,
        "password": password,
        "scope": "openid",
    }).encode()
    
    req = urllib.request.Request(
        "https://login.microsoftonline.com/common/oauth2/token",
        data=body,
        method="POST"
    )
    
    try:
        resp = urllib.request.urlopen(req, context=ctx, timeout=15)
        result = json.loads(resp.read())
        token_result = {"status": "VALID_TOKEN", "token": result.get("access_token","")[:20]+"..."}
    except urllib.error.HTTPError as e:
        err = json.loads(e.read())
        code = err.get("error_codes", [0])[0]
        token_result = {"status": "ERROR", "code": code, "desc": err.get("error_description","")[:80]}
    
    state[email.lower()] = state.get(email.lower(), 0) + 1
    with open(ATTEMPT_FILE, "w") as f:
        json.dump(state, f)
    
    return token_result
Show full SKILL.md (303 more words)Show less

Conditional Access Mapping

After finding valid credential (AADSTS53003/50076/etc), document CA policy:

  • Note which client_id variants are tried (Graph PS, Azure CLI, Office)
  • Note if CA is per-app or universal
  • If universal CA: document as "valid credential, external access blocked by CA - phishing/AiTM required for exploitation"

Confirmation gate

M365/Entra specific. Adds to the hunt-core gate, does not replace it.

NOT confirmation: a valid username from OneDrive enumeration alone (200 / ~57KB body proves the account exists and is licensed, never that it is accessible); an AADSTS error code read in isolation - especially AADSTS50126 (wrong password: proves only that the user EXISTS) and AADSTS50034 (no user). An error code is not a token. A "CA bypass" inferred from a block code (AADSTS53003) without an actually issued access token - 53003 proves the password, it does NOT prove you got past Conditional Access.

IS confirmation - valid credential: ROPC returns an access_token (VALID_TOKEN), OR the login returns one of the strictly-post-validation codes {53003, 50076, 50079, 50158, 530003} (Microsoft emits these only after the password checks out; password confirmed, access gated by MFA/CA). Reproduced.

IS confirmation - Conditional Access bypass: an access_token actually obtained through a client_id / flow the policy fails to cover (not merely a 53003 on one client), reproduced in a clean run.

Chaining

Confirmed credential + obtained token -> hand off to hunt-cloud (Azure / Graph post-auth enumeration) or hunt-federation (AiTM / token replay when CA blocks direct ROPC). A Federated namespace (ADFS) -> hunt-auth legacy-protocol matrix instead of ROPC.

Severity

OutcomeSeverity
CA bypassed and access token obtained (data / Graph access)critical
Valid password confirmed but MFA / CA blocks token issuancehigh
Unauthenticated user-enum / no rate-limit endpoint (enables spray)high

Distill (when confirmed): reusable CA bypass or OneDrive enumeration method, GENERIC, no client host -> python3 scripts/wiki-stage.py --kind technique --slug <slug> --target-page techniques/cloud/azure-ad-enumerate.md (CA bypass: python3 scripts/wiki-stage.py --kind technique --slug <slug> --target-page techniques/cloud/azure-ad-conditional-access-policy.md).

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt/hunt-m365 of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Compare with similar skills

Hunt M365 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt M365 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt M365 this skillEncod3d-Sec/TORCH329—~2kAutomated safety check: PassMIT
Msgraphcodemie-ai/codemie-code294—~4.1kAutomated safety check: PassApache-2.0
aai-cli Microsoft 365aai-labs/agent-barn109—~1.2kAutomated safety check: PassApache-2.0
Workiqmicrosoft/work-iq1k—~15kAutomated safety check: PassCustom licence
Workiq Previewmicrosoft/work-iq1k—~3.3kAutomated safety check: PassCustom licence
Ms365 Tenant Manageralirezarezvani/claude-skills28k1 repos~2.8kAutomated safety check: PassMIT

Similar skills

  • Msgraph

    codemie-ai/codemie-code

    Work with Microsoft 365 services via the Graph API — emails, calendar events, SharePoint sites (read and write), Teams chats and channel messages, OneDrive files, OneNote notebooks, Planner task…

    294 GitHub stars~4.1k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • aai-cli Microsoft 365

    aai-labs/agent-barn

    Guides work with Outlook, OneDrive, SharePoint, Teams, Excel, To Do and Planner through aai-cli's Microsoft Graph commands, starting from which service owns the data.

    109 GitHub stars~1.2k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Workiq

    microsoft/work-iq

    Official

    WorkIQ tools for Microsoft 365 workplace data and actions. An agent skill from microsoft/work-iq.

    1k GitHub stars~15k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Workiq Preview

    microsoft/work-iq

    Official

    WorkIQ tools for Microsoft 365 workplace data and actions. An agent skill from microsoft/work-iq.

    1k GitHub stars~3.3k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Ms365 Tenant Manager

    alirezarezvani/claude-skills

    Microsoft 365 tenant administration for Global Administrators.

    28k GitHub starsUsed in 1 repo~2.8k tokens
    Documents & OfficeAuto-check passed
  • Msgraph Files

    automateyournetwork/netclaw

    Read OneDrive and SharePoint files via the Microsoft 365 MCP server — list folder contents, fetch item metadata, inspect versions and sharing permissions.

    676 GitHub stars~1k tokensUpdated yesterday
    Documents & OfficeAuto-check passed

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

    329 GitHub stars~611 tokensUpdated 1 mo ago
    Auto-check passed
  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • CTF Campaign Driver

    Encod3d-Sec/TORCH

    Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

    329 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Hunt M365

What does Hunt M365 do?

Microsoft 365 / Entra ID attack - tenant discovery, user enumeration via OneDrive differential (2026 verified), AADSTS code reference, Smart Lockout math (hard cap 1-2 attempts/user), ROPC…. Hunt M365 is an agent skill from Encod3d-Sec/TORCH. Microsoft 365 / Entra ID attack - tenant discovery, user enumeration via OneDrive differential (2026 verified), AADSTS code reference, Smart Lockout math (hard cap 1-2 attempts/user), ROPC validation, Conditional Access mapping.

When should I use Hunt M365?

Hunt M365 fits situations like: tasks that involve Cloud office suites.

How do I install Hunt M365 in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill hunt-m365 -a claude-code`. Or copy the skill folder (skills/hunt/hunt-m365 in Encod3d-Sec/TORCH) into .claude/skills/hunt-m365 in your project. Claude Code loads it when a task matches its description.

How do I install Hunt M365 in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill hunt-m365 -a codex`. Or copy the skill folder (skills/hunt/hunt-m365 in Encod3d-Sec/TORCH) into .agents/skills/hunt-m365 in your project. Codex loads it when a task matches its description.

Can I use Hunt M365 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill hunt-m365 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-m365, .gemini/skills/hunt-m365, .github/skills/hunt-m365 and .opencode/skills/hunt-m365 in your project.

What does Hunt M365 need to run?

Going by SKILL.md and its folder, Hunt M365 needs the command-line tools its instructions call (python3 and curl) and credentials named VALID_TOKEN. Our summary lists: Python 3; A credential in VALID_TOKEN.

Does Hunt M365 access the network?

SKILL.md names 2 domains. In commands or code: graph.windows.net and login.microsoftonline.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Hunt M365 safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunt M365 use?

Hunt M365 is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt M365 use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt M365?

Skills that share tags, products or a category with Hunt M365: Msgraph (codemie-ai/codemie-code, 294 stars), aai-cli Microsoft 365 (aai-labs/agent-barn, 109 stars), Workiq (microsoft/work-iq, 1k stars) and Workiq Preview (microsoft/work-iq, 1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt M365?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.