Skip to content

Releases: mbrg/power-pwn

v6.0.0

10 Dec 09:22
d96e7b4

Choose a tag to compare

Release notes (high-level):

General

improved out of the box install and run
improved dependencies installation and on the go guidance + readmes
adaptation to platform changes (cps,PP) + bug fixes
improved & clearer help menu and examples commands
improved results indications for multiple modules (colors, files)
improved cross-OS support
added dependency-handling auto-install files for missing installation errors
automated tools recon on some of the modules for better usability
Improved CPS module:

prefixes updates
word lists updates
improved prefix
updated docs and initial usage clearing
improved tools recon prompt (working again and hopefully better)
env id deep scan
open chat test doesn't run pup on api 401/404 responses unnecessarily (the bots only exists, we know they aren't open)
rotating proxies
get-tenant feature
added template names
retry mechanism when demo website is being tested for robustness
check live bots directly feature
New agentic recon modules

agent builder hunter (scanning and probing)
custom gpt hunter (scan for gpts and tools)
tenant-mcp-recon - ppwn guest recon for shared mcp connectors to discover MCP server tenant works with
llm hound (scanning and probing): mcps & llm wrappers and proxies (AI integration surfaces)
Notes

full docs and wikis tbd
additional updates and possible fixes tbd later on

Full Changelog: v5.0.0...v6.0.0

v5.0.0

21 Aug 13:33
03b17b3

Choose a tag to compare

What's Changed

Full Changelog: v4.0.1...v5.0.0

v4.0.1

08 Aug 12:28
b8e9987

Choose a tag to compare

What's Changed

New Contributors

Full Changelog: v3.0.1...v4.0.1

v3.0.1

09 Aug 14:46

Choose a tag to compare

Update setup.cfg

v3.0.0

07 Aug 14:04

Choose a tag to compare

Major release with Copilot and Copilot studio modules.

Red teaming tools for Copilot M365:

  • Whoami : Current user's info including name, organizational hierarchy, top collaborators, documents and sharepoint sites access, emails, Teams messages, etc.
  • Data dump: Data dump from whoami recon including document, emails and sharepoints sites data dump.
  • Spearphishing: Automated spearphishing. Discover latest conversations and craft highly personalized phishing emails.
  • Chat: Chat with Copilot through the Terminal.
  • Chat automator: Automate chat process with Copilot to further implement automate processes logic.
  • Deep scan: Conducts deep scanning to find open Copilot Studio bots based on domains or tenant IDs.
  • Enum: Utilizes open-source intelligence to compile lists of environment and tenant IDs to be used by the other Copilot Studio scanning sub-modules.

v2.1.5

18 Apr 20:34

Choose a tag to compare

What's Changed

Full Changelog: v2.1.4...v2.1.5

v2.1.4

06 Dec 21:00

Choose a tag to compare

Fix authentication debug log exception

v2.1.3

17 Aug 12:59

Choose a tag to compare

Split powerpwn dump command into two different commands:

  1. powerpwn recon - Recon for available data connections
  2. powerpwn dump - Dump content for all available connection from recon

v2.1.2

01 Aug 10:52

Choose a tag to compare

Merge pull request #22 from mbrg/cleanup

Cleanup

v2.1.1

28 Jul 13:44

Choose a tag to compare

fix ver