{"repo":"nyxgeek/onedrive_user_enum","free":true,"listed":false,"github":"https://github.com/nyxgeek/onedrive_user_enum","clone":"git clone https://github.com/nyxgeek/onedrive_user_enum.git","description":"onedrive user enumeration - pentest tool to enumerate valid o365 users","language":"Python","stars":764,"topics":["pentesting","enumeration","user-enumeration","osint","o365","onedrive","office365","onedrive-users","azure","m365"],"license":"GPL-3.0","category":"security-tools","readme_excerpt":"onedrive user enum v2.10 enumerate valid onedrive users For a full rundown of the enumeration technique and OneDrive enum, check out the blog here: https://www.trustedsec.com/blog/onedrive-to-enum-them-all/ If you are looking for the old, non-database vesion of OneDrive Enum, you can find it here: https://github.com/nyxgeek/simple scanners New features in 2.10: Remote MySQL DB logging option -- log to a remote database PAUSEFILE -- if pausefile is present (/tmp/PAUSEFILE), pause enumeration Truncate userlist to x characters -- johnsmith - johnsmi New features in 2.00: Local Database (sqlite3) Auto-lookup of tenants (thanks @DrAzureAD and @thetechr0mancer) Read in file OR folder of files Append -- easily create 'jsmith1' 'jsmith2' sprays Skip-Tried (de-dupe) -- remove previously tried usernames Kill-After -- cancel a userlist if no usernames identified within 'x' attempts OneDrive Enumeration overview: OneDrive users have a file share URL with a known location: https://acmecomputercompany-my.sharepoint.com/personal/lightmand acmecomputercompany com/ layouts/15/onedrive.aspx In this instance, the username is 'lightmand' and the domain is 'acmecomputercompany.com'. If a user has logged into OneDrive, this path will exist and return a 403 status code. If they have not, or the user is invalid, it will return a 404. The results may vary depending on how widely used OneDrive is within an org. Currently it is the most reliable user-enumeration method that I'm aware of (office365usere","default_branch":null,"files":null,"tree":[],"storefront":"/r/nyxgeek","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/nyxgeek/onedrive_user_enum/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}