-
Notifications
You must be signed in to change notification settings - Fork 63
OAuthPermissions‐Analyzer
evild3ad edited this page Oct 20, 2025
·
4 revisions
OAuthPermissions-Analyzer.ps1 is a PowerShell script utilized to simplify the analysis of M365 OAuth Permissions extracted via Microsoft-Extractor-Suite by Invictus-IR.

Fig 1: OAuthPermissions-Analyzer

Fig 2: Application Permissions

Fig 3: Delegated Permissions → eM Client (Traitorware)

Fig 4: ClientDisplayName / AppId (Stats)

Fig 5: PermissionType / Permission (Stats)

Fig 6: PublisherName / ClientDisplayName (Stats)

Fig 7: Statistics
M365_Oauth_Apps - Repository of suspicious Enterprise Applications (BEC)
Microsoft Graph permissions reference
App consent grant investigation