{"repo":"mbrg/power-pwn","free":true,"listed":false,"github":"https://github.com/mbrg/power-pwn","clone":"git clone https://github.com/mbrg/power-pwn.git","description":"An offensive/defense security toolset for discovery, recon and ethical assessment of AI Agents","language":"Python","stars":1183,"topics":["pentesting","redteam","hacking","lowcode","nocode","m365","microsoft365","powerapps","hacking-tool","redteaming"],"license":"MIT","category":"workflow-automation","readme_excerpt":"Maintained by: Secure AI Agents Everywhere. Overview Power Pwn is an offensive and defensive security toolset for Microsoft 365 Power Platform and AI services. Key Features, among others: - 💾 PowerDump : Comprehensive tenant scanning and data collection - 🚪 BackDoor : Deploy backdoor flows for persistent access to Power Platform environments - 🦠 NoCodeMalware : Create and deploy malicious Power Platform artifacts without writing code - 🎣 PowerPhishing : Abuse Power Platform for phishing campaigns and credential harvesting - 🤖 Copilot Studio Hunter : Discover and test misconfigured Copilot Studio bots exposed to unauthenticated users - 🤖 Custom GPT Hunter : Enumerate and analyze custom GPTs - 🤖 Agent Builder Hunter : Discover publicly available Agent Builder deployments and enumerate their capabilities - 🔎 LLM Hound : Discover publicly exposed MCPs & AI middleware across the internet using Shodan - 🎯 Copilot M365 : Test Microsoft 365 Copilot for unauthorized data retrieval - 📄 Power Pages : Identify misconfigured Power Pages that leak Dataverse tables Please review the tools documentation for the full list of features: Check out our Wiki for comprehensive documentation, guides, and related talks! A review of Power Pwn's PowerDump module is available here: Installation For standard usage, install with: For developers and advanced usage , see our comprehensive Installation Guide which covers: - Full automated installation (Python + external tools) - Module-specific dep","default_branch":null,"files":null,"tree":[],"storefront":"/r/mbrg","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/mbrg/power-pwn/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}