dirkjanm/askWAM
Ask the Web Account Manager (WAM) for Entra ID tokens
About the project
Tool for requesting Microsoft Entra access tokens silently via Windows Web Account Manager (WAM) without interactive authentication. Ships as a .NET client, a native x64 client, and a Beacon Object File for Cobalt Strike.
Useful for
- Enumerate available WAM accounts on a host via --enum
- Request a Graph token for a specific user by username or account-id
- Load the BOF into Cobalt Strike to obtain tokens during a pentest
README summarized by DeepSeek V4.1 Flash. Details may be inaccurate.
Why it’s trending
- 5 stars so far today, about 6 expected by the end of the day.
- The spike has held for 2 days in a row — not a one-off blip.
- The repository is 7 days old and already has 130 stars.
- Recent forks include notable developers: @ASkyeye (578 followers), @Cyb3r-Monk (441 followers).
Stars per day
Bars are daily stars, the line is the usual pace. Red marks spike days.
Numbers
- Total stars
- 130
- Stars in a day
- 6
- Forks
- 15
- Issues and pull requests
- 1
- Watchers
- 0
- Language
- C
- License
- MIT
- Created
- September 11, 2026
- Last push
- September 11, 2026
Star trust
Growth looks organic: forks and discussion are in line with active projects, and stars arrive unevenly, the way people give them.
These are heuristics, not a verdict: we judge by the repository’s behavior, not by a list of stargazers.
Spotted in
- September 17, 2026Top new repositories this week: #69
- September 16, 2026Top new repositories this week: #91
- September 15, 2026Top new repositories this week: #110
- September 14, 2026Top new repositories this week: #156
Similar projects
-
9.7
cloudflare/security-audit-skill
A coding-agent skill that turns the agent into a security auditor, running a multi-phase code audit with independently verified, machine-readable findings.
-
6.6
yynxxxxx/gpt_sub_analysis
A guide to analyzing the ChatGPT iOS subscription flow: it describes intercepting the buyProduct request via Reqable and SSL Kill Switch 3 and rewriting the offerName and salableAdamId fields to obtain the Pro 20x…
-
5.8
ctdal/cve-2026-41940-PoC
PoC exploit for CVE-2026-41940, a critical authentication bypass in cPanel & WHM (CVSS 10.0) that grants unauthenticated root-level WHM access by injecting CRLF sequences into server-side session files.
-
5.3
BennyThink/NFCX
Cross-platform GUI desktop app for NFC card work: reader discovery, MIFARE Classic reads, dumps, key management, and key recovery. For cards you own or are authorized to test.
-
4.9
NationalSecurityAgency/ghidra
A software reverse engineering framework from the NSA: disassembly, decompilation, graphing and scripting for analyzing compiled code on Windows, macOS and Linux.
-
4.6
shinthink/blitzstrike
A TypeScript/Bun MCP server packaging a pentest methodology into three tiers: attack-surface reconnaissance, source-to-sink tracing, and live validation of findings before reporting.