DEBULL: Phishing-as-a-Service Platform for Device Code Attacks
DEBULL is a reusable tooling layer that packages Storm-2372-style identity tradecraft into a PhaaS platform. It provides campaign-facing and operator-facing infrastructure, using…
DEBULL is a reusable tooling layer that packages Storm-2372-style identity tradecraft into a PhaaS platform. It provides campaign-facing and operator-facing infrastructure, using…
EvilTokens is a phishing kit that steals Microsoft 365 tokens through the OAuth device code flow. It also provides AI-powered analytics services…
LevelBlue advises blocking the device code authentication method globally in Conditional Access Policies to prevent device code phishing. If the flow is…