The Microsoft Graph API can be a dangerous accomplice: combined with the right permissions, attackers can control everything in Microsoft 365. But it is still hard to detect and prevent Graph API related attacks. In my research | investigated and simulated MS Graph related attacks; parts of this work | will share in this presentation. Take a peek behind the curtains of how adversaries (ab)use MS Graph API to breach corporate defences, implant persistence mechanisms, and exfiltrate sensitive data. Through a live demonstration, we will simulate the execution of potential attack scenarios, providing invaluable insights into the adversary's playbook. Explore attack scenarios from the field and learn how to detect and prevent against such an attack. Are you ready to dive into real world threat actors’ tactics?