module

OneDrive Sync Provider Enumeration Module

Disclosed
N/A
Created
2021-01-29

Description

This module will identify the Office 365 OneDrive endpoints for both business and personal accounts
across all users (providing access is permitted). It is useful for identifying document libraries
that may otherwise not be obvious which could contain sensitive or useful information.

Author

Stuart Morgan stuart.morgan@mwrinfosecurity.com

Platform

Windows

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:


msf > use post/windows/gather/enum_onedrive
msf post(enum_onedrive) > show actions
...actions...
msf post(enum_onedrive) > set ACTION < action-name >
msf post(enum_onedrive) > show options
...show and set options...
msf post(enum_onedrive) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.