DEVICE CODE PHISH — RFC 8628 ABUSE LAB

Training · No Live Endpoints
Attacker terminal Victim browser (real MS domain)

// Phase 0 · idle. Press START to launch the campaign.

🔒 about:blank
Victim browser idle.
The campaign hasn't started yet.
0Attacker requests
device code
1Phishing email
delivered
2Victim visits
real MS page
3Victim authenticates
+ MFA
4Tokens issued
to attacker
5Post-compromise
access
Click Start campaign to walk through how an attacker abuses RFC 8628's device authorization grant against a Microsoft 365 user.