Blog & Guides
Practical cybersecurity articles, step-by-step guides, and quick-reference cheat sheets — from Active Directory hardening to Microsoft 365 and zero trust. Written by someone who's done the work. No hype, no fluff.
2 results for “device code phishing” · Clear
Anatomy of a Device Code Phishing Email: A Real Investigation
A phishing email with no malware, no cloned login page and a clean URL reputation would still have handed an attacker a fully authenticated Microsoft 365 session — without ever seeing the password, and without the victim's MFA slowing them down. This is a captured, screen-by-screen walkthrough of a device code phishing email (the Cloudflare hold-to-continue gate, the copied Microsoft device code, the genuine sign-in page) plus the detection, hardening, and full mitigating and compensating controls to stop it.
Ghost Phishing: How the EvilTokens Campaign Hides in the Browser to Hijack Microsoft 365 Accounts
A new "ghost phishing" wave from the EvilTokens kit is slipping past email security by keeping its payload AES-encrypted until it renders in the victim's browser, then using Microsoft device-code phishing to take over Microsoft 365 accounts without ever stealing a password. This guide breaks down how the technique works, why traditional URL and email controls miss it, who is being hit, and the concrete detection and hardening steps to defend your tenant.