Skip to content
zer0bytePublic

About

Read-only SharePoint Online and M365 reconnaissance from the browser console. No app registration, no install, search-driven.

Topics

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

2 Commits

Folders and files

Repository files navigation

SPRecon

Read-only SharePoint Online and M365 reconnaissance from the browser console. No app registration, no token, runs on the session you are already signed into.

Released by Zer0byte. Authorized security assessments only.

READ-ONLY · NO TOKEN · ZERO INSTALL · SINGLE FILE

Sibling of ADORecon, same architecture and same safety model.


What it is

SPRecon is one JavaScript file you paste into the DevTools console on a tab that is already logged into SharePoint Online. It rides the live session cookies and is search-driven: it uses the SharePoint Search API, which is scoped to what the signed-in account can already see, to inventory the tenant, surface externally shared content, flag broad-access grants and guest accounts, and sweep document content for secrets.

It writes nothing. Every request is a GET, with one exception gated to the read-only Search API.

Screenshots

Config Secrets
config secrets
Recon Log
recon log

Open sample-report.html in a browser to view a sample exported report.

Why search-driven

SharePoint's Search index already covers file content across the tenant, and it only returns what the current identity is allowed to see. That makes it the fastest and most realistic recon surface: one query reaches content in sites and libraries you would otherwise have to crawl one by one, and the results reflect exactly the access the assessed identity holds.

Safety model

  • The transport function only issues GET.
  • The one non-GET path is gated by an allow-list to the Search API.
  • No code path shares, grants, uploads, deletes, or changes permissions.

Usage

  1. Sign into https://<tenant>.sharepoint.com.
  2. Open DevTools with F12, then the Console tab.
  3. Paste the full contents of sprecon.js and press Enter.
  4. Configure modules and scope on the Config tab, then press Run recon.
  5. Browse the Secrets and Recon tabs, and export with JSON or HTML report.

The raw findings object is available at window.SPRecon.data.

Modules

Secret modules

  • Content secret search: queries the index for secret patterns (-----BEGIN, AccountKey=, AKIA, ghp_, AIzaSy, connection strings, and more), then runs the secret engine over each hit's snippet.
  • High-signal file sweep: finds .env, web.config, appsettings.json, .pem, .pfx, id_rsa, .npmrc and similar by name and extension, and for same-host files pulls and scans the content.

Recon modules

  • Site inventory: enumerates every site collection the account can reach.
  • External exposure: queries the ViewableByExternalUsers index property to surface content shared beyond the tenant (anonymous "anyone" links and external shares), and lists guest accounts on the current site.
  • Broad-access grants: reads role assignments on the current site and flags the "Everyone", "Everyone except external users", and "All authenticated" claims, tagged by the role they hold.
  • Users and guests: enumerates site users, flags external guest accounts and site-collection admins, and notes whether the current identity is an admin.

Output and reporting

Same interface as ADORecon: severity counts, a Firm filter for high-confidence findings, search, mask toggle, resizable columns, and click-to-copy values. The HTML report is a sectioned deliverable (posture findings, identity, sites, external exposure, grants, guests, secrets), with a deep link on every finding.

Detection tiers

Secret rules are tagged firm (fixed-format tokens, low false-positive) or heuristic (entropy and format guesses, review-required). Findings are de-duplicated globally. Rich-text is cleaned of inline base64 images and HTML before scanning.

Limitations

  • OneDrive lives on -my.sharepoint.com, a separate origin. Search still sees OneDrive items, but full-content fetch is limited to the SharePoint host origin.
  • The grants and guests modules read the current site by default. Iterating every discovered site is a heavier follow-up.
  • Anonymous-link detection uses the ViewableByExternalUsers index property rather than per-item sharing calls, which is reliable and read-only but coarser than walking each item's sharing settings.

Authorized use

For authorized security assessments only. Run it only against tenants you own or are contracted to test. You are responsible for having permission.

License

See LICENSE.

Author

Built and maintained by Zer0byte.

About

Read-only SharePoint Online and M365 reconnaissance from the browser console. No app registration, no install, search-driven.

Topics

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages