Skip to content

Adding TRR for Authorization Code Phishing - #21

Merged
vanvleeta merged 15 commits into
tired-labs:mainfrom
azotheblue:trr-oauth-authcode-phishing
Aug 17, 2026
Merged

Adding TRR for Authorization Code Phishing#21
vanvleeta merged 15 commits into
tired-labs:mainfrom
azotheblue:trr-oauth-authcode-phishing

Conversation

@azotheblue

Copy link
Copy Markdown
Contributor

Hello,

This pull request adds a Technique Research Report (TRR) covering OAuth Authorization Code Phishing, including documentation of the ConsentFix procedure within Microsoft Entra ID environments. The report outlines the mechanics of the authorization code flow and describes how attackers can abuse redirect behavior to obtain authorization codes and redeem them for access tokens.

This is my first contribution to the repository, so please let me know if there are any formatting issues or changes that would improve the submission. I appreciate any feedback from the maintainers.

@azotheblue
azotheblue requested a review from a team March 11, 2026 18:31
@mjwhitta

Copy link
Copy Markdown
Contributor

Sorry for the delay. I approved the workflow and looks like there are some linter changes that need addressed. Looks mostly like line-wrapping and a few inline-urls.

@vanvleeta vanvleeta left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Excellent first draft! Thank you for the submission!

Comment thread reports/trr0000/azr/README.md Outdated
Comment thread reports/trr0000/azr/README.md Outdated
Comment thread reports/trr0000/azr/README.md Outdated
Comment thread reports/trr0000/azr/README.md Outdated
Comment thread reports/trr0000/azr/README.md Outdated

@dumpst3rfir3 dumpst3rfir3 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I agree with other comments, great work! I'm not sure I had much to add to what's already been said, but I left a couple of comments in there.

Comment thread reports/trr0000/azr/README.md Outdated
Comment thread reports/trr0000/azr/README.md Outdated
@azotheblue

Copy link
Copy Markdown
Contributor Author

I think I fixed all of the issues with this new commit. If there are more issues please let me know and I will be happy to fix! Thanks again for the review!

Comment thread reports/trr0000/azr/README.md Outdated
Comment thread reports/trr0000/azr/README.md Outdated

@mjwhitta mjwhitta left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just a couple small things. Ultimately this looks really good!

Comment thread reports/trr0000/azr/README.md Outdated
Comment thread reports/trr0000/azr/README.md Outdated
Comment thread reports/trr0000/azr/README.md Outdated
dumpst3rfir3
dumpst3rfir3 previously approved these changes May 27, 2026

@dumpst3rfir3 dumpst3rfir3 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. I had some nit-picky comments/questions, but feel free to ignore.

Comment thread reports/trr0000/azr/README.md Outdated
Comment thread reports/trr0000/azr/README.md
Comment thread reports/trr0000/azr/README.md Outdated
@dumpst3rfir3

Copy link
Copy Markdown
Contributor

Really sorry for the long delay, btw.

@azotheblue

Copy link
Copy Markdown
Contributor Author

Fresh batch of updates. Thanks for the feedback!

If you see any other issues, please let me know!

Comment thread reports/trr0000/azr/README.md
@mjwhitta

Copy link
Copy Markdown
Contributor

I think this LGTM, but I believe @vanvleeta might have something to say about the DDM. I can't tell if it was made with the same software he typically uses (arrows?). If he approves, then I will also approve.

@vanvleeta vanvleeta left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking great! Last few suggestions!

Comment thread reports/trr0000/azr/README.md Outdated
Comment thread reports/trr0000/azr/README.md Outdated
Comment thread reports/trr0000/azr/README.md
Comment thread reports/trr0000/azr/README.md
Co-authored-by: Cursor <cursoragent@cursor.com>
mjwhitta
mjwhitta previously approved these changes Aug 5, 2026

@mjwhitta mjwhitta left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Newest changes LGTM.

@vanvleeta vanvleeta left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks awesome, ready to go IMHO!

@vanvleeta
vanvleeta merged commit 91e3112 into tired-labs:main Aug 17, 2026
1 check passed
trr-bot Bot pushed a commit that referenced this pull request Aug 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

4 participants