Domain Activity
New Today
—
New This Week
—
Total Domains
—
Recently Observed Domains
Loading…
Recent Screenshots
Loading…
No results yet. Check back soon.
Contact
Email
[email protected]
LinkedIn
linkedin.com/in/jalen-vaughn
What Phishboard Does
Phishboard is a threat intelligence tracker for device code phishing infrastructure. It continuously queries URLScan.io for newly observed phishing pages using this technique, fingerprints the kit behind each one, and publishes defanged indicators of compromise to a
public GitHub Gist
for other researchers and defenders to use.
What Is Device Code Phishing
Device code phishing abuses a legitimate OAuth 2.0 flow (RFC 8628) built for devices without keyboards, like smart TVs. An attacker requests a device code, then convinces a victim to enter it on the real Microsoft login page. The victim signs in normally, and the attacker's client receives a valid access token, no password required.
Because the login page is genuinely Microsoft's, this technique bypasses MFA and standard phishing defenses, and is increasingly used against corporate Microsoft 365 accounts.
How It Works
- The attacker requests a device code and starts polling Microsoft in the background.
- The victim is lured, often through a fake shared document or meeting invite, into visiting the real Microsoft sign-in page and entering the code.
- The victim completes sign-in and MFA normally.
- Microsoft issues a valid access token to the attacker's client instead of the victim's device.
- The attacker uses that token to access mail, files, and other Microsoft 365 resources.
Disclaimer
This project is published for security research and educational purposes only. It is not a takedown service, and the data shown is not guaranteed to be complete or current. Use it at your own discretion.
Infrastructure Intelligence
Domain Activity
New Today
—
New This Week
—
Total Domains
—
Infrastructure Clusters
Loading cluster data…
All Tracked Domains
Loading…