Read-only SharePoint Online and M365 reconnaissance from the browser console. No app registration, no token, runs on the session you are already signed into.
Released by Zer0byte. Authorized security assessments only.
READ-ONLY · NO TOKEN · ZERO INSTALL · SINGLE FILE
Sibling of ADORecon, same architecture and same safety model.
SPRecon is one JavaScript file you paste into the DevTools console on a tab that is already logged into SharePoint Online. It rides the live session cookies and is search-driven: it uses the SharePoint Search API, which is scoped to what the signed-in account can already see, to inventory the tenant, surface externally shared content, flag broad-access grants and guest accounts, and sweep document content for secrets.
It writes nothing. Every request is a GET, with one exception gated to the read-only Search API.
| Config | Secrets |
|---|---|
![]() |
![]() |
| Recon | Log |
|---|---|
![]() |
![]() |
Open
sample-report.htmlin a browser to view a sample exported report.
SharePoint's Search index already covers file content across the tenant, and it only returns what the current identity is allowed to see. That makes it the fastest and most realistic recon surface: one query reaches content in sites and libraries you would otherwise have to crawl one by one, and the results reflect exactly the access the assessed identity holds.
- The transport function only issues
GET. - The one non-GET path is gated by an allow-list to the Search API.
- No code path shares, grants, uploads, deletes, or changes permissions.
- Sign into
https://<tenant>.sharepoint.com. - Open DevTools with F12, then the Console tab.
- Paste the full contents of
sprecon.jsand press Enter. - Configure modules and scope on the Config tab, then press Run recon.
- Browse the Secrets and Recon tabs, and export with JSON or HTML report.
The raw findings object is available at window.SPRecon.data.
Secret modules
- Content secret search: queries the index for secret patterns (
-----BEGIN,AccountKey=,AKIA,ghp_,AIzaSy, connection strings, and more), then runs the secret engine over each hit's snippet. - High-signal file sweep: finds
.env,web.config,appsettings.json,.pem,.pfx,id_rsa,.npmrcand similar by name and extension, and for same-host files pulls and scans the content.
Recon modules
- Site inventory: enumerates every site collection the account can reach.
- External exposure: queries the
ViewableByExternalUsersindex property to surface content shared beyond the tenant (anonymous "anyone" links and external shares), and lists guest accounts on the current site. - Broad-access grants: reads role assignments on the current site and flags the "Everyone", "Everyone except external users", and "All authenticated" claims, tagged by the role they hold.
- Users and guests: enumerates site users, flags external guest accounts and site-collection admins, and notes whether the current identity is an admin.
Same interface as ADORecon: severity counts, a Firm filter for high-confidence findings, search, mask toggle, resizable columns, and click-to-copy values. The HTML report is a sectioned deliverable (posture findings, identity, sites, external exposure, grants, guests, secrets), with a deep link on every finding.
Secret rules are tagged firm (fixed-format tokens, low false-positive) or heuristic (entropy and format guesses, review-required). Findings are de-duplicated globally. Rich-text is cleaned of inline base64 images and HTML before scanning.
- OneDrive lives on
-my.sharepoint.com, a separate origin. Search still sees OneDrive items, but full-content fetch is limited to the SharePoint host origin. - The grants and guests modules read the current site by default. Iterating every discovered site is a heavier follow-up.
- Anonymous-link detection uses the
ViewableByExternalUsersindex property rather than per-item sharing calls, which is reliable and read-only but coarser than walking each item's sharing settings.
For authorized security assessments only. Run it only against tenants you own or are contracted to test. You are responsible for having permission.
See LICENSE.
Built and maintained by Zer0byte.



