You Know Kali Linux. Now Meet Kali 365.
Every penetration tester knows Kali Linux. The Debian-based distribution, maintained by Offensive Security, ships with hundreds of pre-installed security tools — Nmap, Metasploit, Burp Suite, Wireshark — and has become the de facto standard platform for security professionals assessing network and application security. When a client asks for a pen test, the engagement almost certainly starts with a Kali machine.
But here's what most IT teams don't realise: the security community has quietly assembled an equivalent arsenal specifically for Microsoft 365. There is no single distribution called "Kali 365" — instead, it is an informal but very real collection of open-source tools, techniques, and attack playbooks that have emerged over the past five years, all purpose-built to assess, probe, and exploit Microsoft 365 tenants. Taken together, they represent a complete attack surface toolkit for the cloud environment that now houses your emails, documents, identities, and increasingly, your AI-powered workflows.
Understanding what these tools can do is the first step to understanding why your M365 security posture matters more than you probably think — and why deploying Microsoft Copilot into an unaudited tenant is a significant risk.
The Kali 365 Arsenal: What's In It
The Kali 365 toolkit is not curated by any single organisation — it has grown organically from the work of security researchers, red team practitioners, and Microsoft's own security community. Here are the tools that appear in virtually every M365 pen test engagement:
What a Kali 365 Engagement Looks Like in Practice
When a security team picks up the Kali 365 toolkit and points it at a target tenant — with authorisation — the engagement typically follows a structured attack chain. Understanding this chain is valuable because it shows exactly which security controls, if present, would stop the attack at each stage.
Phase 1: External Reconnaissance (0–5 minutes). Before any authentication attempt, tools like o365spray and AADInternals can confirm whether a target domain is an M365 tenant, enumerate valid email addresses (without triggering failed login attempts), identify federation configuration, and even determine which Microsoft authentication flows are enabled. This information is gathered entirely from the public internet, with no credentials required and no log entries generated in the target tenant.
Phase 2: Initial Access (5–20 minutes). The most common initial access technique in modern M365 attacks is not brute-force — it is phishing for OAuth tokens using the Device Code Flow. An attacker sends a legitimate-looking email inviting the target to "verify their Microsoft account." The link goes to Microsoft's own authentication pages, and if the target completes the flow, the attacker receives a valid, long-lived refresh token without ever seeing the target's password. MFA does not prevent this attack — the victim completes MFA themselves as part of the flow. This technique has been used in real-world nation-state attacks, including the 2022 campaign attributed to Midnight Blizzard (formerly APT29).
Phase 3: Internal Enumeration (20–30 minutes). With a valid token, GraphRunner and ROADtools immediately begin mapping the environment. Within minutes, an attacker can see every user, group, and service principal in the tenant; identify admin accounts and their MFA status; enumerate all SharePoint sites and their sharing configurations; read the contents of OneDrive folders; and extract Teams conversation history. The Microsoft Graph API is designed for legitimate application access — it returns exactly the data a threat actor needs, wrapped in clean JSON responses.
Phase 4: Privilege Escalation and Persistence (30–60 minutes). If any admin account has no MFA, or if there are service accounts with excessive privileges, the attacker can escalate quickly. AADInternals can create persistent backdoor accounts, modify conditional access policies, and extract ADFS signing certificates. Once this stage is reached, remediation requires a full identity rebuild — not just a password reset.
"In nine out of ten M365 pen tests, we find a path from unauthenticated external attacker to tenant-wide data access in under one hour. The tools are freely available, the misconfigurations are consistent, and most organisations have no detection in place for any of it." — Red Team Lead, UK Cybersecurity Consultancy
Why M365 Is Such a Rich Target
The reason Kali 365 has become such a mature toolkit is simple: Microsoft 365 is where the data is. More than 400 million commercial seats now run some combination of Exchange Online, SharePoint, Teams, OneDrive, and Entra ID. For most organisations, M365 is not just a productivity tool — it is the single system of record for email communications, document storage, HR data, financial records, legal files, and strategic plans. For an attacker, a compromised M365 tenant is not a foothold — it is the prize itself.
The challenge for defenders is that M365 is also a legitimate cloud service, consumed through standard web protocols. There is no perimeter to defend in the traditional sense. Authentication flows, API calls, and data access all happen through the same interfaces that authorised users and applications use every day. This means conventional network security tools — firewalls, IDS/IPS, network segmentation — provide almost no protection against Kali 365-style attacks. The defence must be in the identity layer, the data governance layer, and the configuration of the service itself.
And this is precisely where most organisations are weakest. The Microsoft 365 security configuration surface is enormous — conditional access policies, authentication methods, sharing settings, DLP policies, sensitivity labels, admin role assignments, service principal permissions, legacy protocol controls, and dozens more. Each misconfiguration is a potential door. And as we have shown, Kali 365 has a tool specifically designed to find every one of them.
The Copilot Multiplier
The calculus changed again with the introduction of Microsoft 365 Copilot. Before Copilot, an attacker who compromised a standard user account needed to manually search for interesting documents — browsing SharePoint sites, reading through email threads, navigating OneDrive folders. It was slow, noisy, and incomplete. With Copilot, that same compromised account becomes a powerful intelligence tool. A simple natural language query — "summarise the board papers from the last six months" or "what are the key terms in our pending M&A agreement?" — will surface the most relevant confidential documents from across the entire tenant. What used to take hours of manual searching takes seconds. The oversharing problems that Kali 365 tools identify become catastrophically worse the moment Copilot is activated.
This is why the combination of a Kali 365-style external security assessment and an internal configuration audit — such as that provided by Copilot SafeScan — represents the complete security picture every organisation deploying Copilot needs before go-live.
What This Means for Your Organisation
The existence of the Kali 365 toolkit is not a reason to avoid Microsoft 365 — the productivity and collaboration benefits are real, and the security controls available in the platform, properly configured, are genuinely strong. But "properly configured" is doing a lot of work in that sentence. The tools described in this article succeed not because Microsoft's platform is inherently insecure, but because the default configuration of M365, combined with years of organic growth and ad-hoc provisioning decisions, leaves almost every tenant with exploitable weaknesses.
The question every IT leader should be asking is not "could our tenant be attacked?" — it demonstrably could be, by freely available tools that any motivated attacker can download and run. The question is "do we know where our weaknesses are, and have we closed them?" For organisations that have never run a formal M365 security assessment, the honest answer is almost certainly no.
In the follow-up to this article, we walk through exactly which controls stop Kali 365 in its tracks — and how to check whether those controls are in place in your tenant right now.