Skip to main content

PyPi Version Python Version GitHub Sponsors Twitter LinkedIn

CredSpy

Enumerate Microsoft Entra ID authentication methods for email addresses using the public GetCredentialType API. This is the same endpoint the Microsoft login page uses when you enter a username. In contrast to most tools using the GetCredentialType method, CredSpy also shows the authentication methods supported for existing accounts.

Useful for security assessments: user enumeration, preferred auth method discovery, and identifying accounts with password, Remote NGC (e.g. Passwordless Push Notification), FIDO2/passkeys, or certificate auth.

Table of contents

Installation

Requires Python 3.10+.

pipx (recommended):

# Install pipx (skip this if you already have it)
apt install pipx
pipx ensurepath
# From PyPI (recommended)
pipx install credspy

# Or from GitHub
pipx install git+https://github.com/RedByte1337/CredSpy.git

# From a local clone
git clone https://github.com/RedByte1337/CredSpy.git
cd CredSpy
pipx install .

pip:

pip install .
# or run without installing
pip install -r requirements.txt
python credspy.py ...

After installation, run credspy from anywhere:

credspy -h

Usage

# Single email
credspy user@example.com

# File of emails (one per line, # for comments)
credspy emails.txt

# Through a proxy (SSL verification disabled for MITM tools)
credspy emails.txt --proxy http://127.0.0.1:8080

# Export results to CSV
credspy emails.txt --csv results.csv

# Save filtered email lists (combinable)
credspy emails.txt \
  --save-existing existing.txt \
  --save-ngc ngc.txt \
  --save-password-preferred password-preferred.txt

Options

Flag Description
target Email address or path to a text file
--proxy URL Route all traffic through a proxy; disables SSL verification (Format: http://127.0.0.1:8080)
--no-color Disable colored terminal output
--csv FILE Write results to CSV
--save-existing FILE Save emails that exist
--save-ngc FILE Save emails with RemoteNGC (e.g. passwordless push-notification) supported
--save-password-preferred FILE Save existing emails with password as preferred method
--skip-ngc Disable RemoteNGC checks (avoids push notifications when RemoteNGC is the preferred method; this also disables NGC discovery)

If any output file already exists, you are prompted to confirm overwrite (Y/n).

Output

Results stream to the terminal as each email is checked:

redbyte@e-corp.com       | Preferred: Fido (7)       | Supported: Password, RemoteNGC (PushNotification), Fido (Count: 3)
nonexistent@e-corp.com   | IfExistsResult: NotExist (1)
admin@e-corp.com         | Preferred: Password (1)   | Supported: Password, RemoteNGC (PushNotification)
alice@e-corp.com         | Preferred: RemoteNGC (2)  | Supported: Password, RemoteNGC (PushNotification)
bob@e-corp.com           | Preferred: Fido (7)       | Supported: Password, Fido (Count: 5), Certificate

If the email account exists, the first column after the email address will show the preferred authentication method for the user. The last column will list the other supported authentication methods such as Password, RemoteNGC, Fido (=PassKeys), and Certificate authentication.

All of this information is very useful to take into consideration when preparing for phishing attacks.

For Fido authentication, the number of entries in the AllowList of the FidoParams returned by Microsoft is shown. This can be used as an indicator to know how many Fido auth methods the user has enrolled. However, it seems like this also includes deleted Fido keys which are not linked to the account anymore.

A summary is printed at the end:

--- Summary ---
Exists: 6/7
Throttled: 0/7
Preferred: Fido 3/6, Password 2/6, ...
Supported: Password 6/6, RemoteNGC 1/6, Fido 3/6, Certificate 2/6
DomainType: Managed 6/6

--- Output files ---
CSV (results.csv): 7 entries

CSV columns

Email, Exists, PreferredType, HasPassword, RemoteNGC, HasFido, HasCertAuth, DomainType

  • Exists — enum name (Exists, NotExist, …)
  • RemoteNGC — PushNotification / ListSessions when known, otherwise True/False

How it works

  1. Fetch a session context (sCtx) from the Microsoft OAuth authorize page
  2. POST each username to login.microsoftonline.com/common/GetCredentialType
  3. Parse credential flags and print / export results

No authentication required. This uses the same unauthenticated flow as the login UI.

Disclaimer

This tool is intended for authorized security testing and research only. Only use it against tenants and accounts you own or have explicit written permission to test. The authors are not responsible for misuse.

Metadata

Release files for credspy 1.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for credspy 1.1.1
File Size Uploaded
credspy-1.1.1.tar.gz 20.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for credspy 1.1.1
File Interpreter ABI Platform
credspy-1.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 30.8 kB

Release files / credspy-1.1.1.tar.gz

Download URL credspy-1.1.1.tar.gz
Size 20.4 kB
Tags Source
SHA-256 checksum
How to use checksums
7d109d4249408d5fbbf4adfc5903675115bad42e7ebe2304af093d535b254065
BLAKE2b-256 checksum
How to use checksums
b0d13402dfede8efe94ff9824ab4ea0ab998ec12aaa0d7e6283b87a52144b0f2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.9.21 {"installer":{"name":"uv","version":"0.9.21","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":null,"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / credspy-1.1.1-py3-none-any.whl

Download URL credspy-1.1.1-py3-none-any.whl
Size 10.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
01c6924c53a2486ee999188b22fb223d370f022db3735c01a4b933858f9af99d
BLAKE2b-256 checksum
How to use checksums
34311671e3482817b3bf44c19b2bb1753447f7c7084ffbf802976588c0bd092a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.9.21 {"installer":{"name":"uv","version":"0.9.21","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":null,"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

This release

1.1.1 This release

2 release files

1.1.0

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page