DEVICE CODE
PHISH
— RFC 8628 ABUSE LAB
Training · No Live Endpoints
■
Attacker terminal
■
Victim browser (real MS domain)
// Phase 0 · idle. Press START to launch the campaign.
🔒 about:blank
Victim browser idle.
The campaign hasn't started yet.
0
Attacker requests
device code
1
Phishing email
delivered
2
Victim visits
real MS page
3
Victim authenticates
+ MFA
4
Tokens issued
to attacker
5
Post-compromise
access
▶ Start campaign
↺ Reset
⏵ Auto-play
Click
Start campaign
to walk through how an attacker abuses RFC 8628's device authorization grant against a Microsoft 365 user.