Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
AzureAD-Attack-Defense — This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected. | Kitploit
Tools/GitHubGitHub/cloud-architekt/azuread-attack-defense
Authentication & AuthorizationDefensive ToolsPassword AttacksConfiguration AuditingCloud SecurityIdentity & Access Management (IAM)Learning & EducationCurated Resources

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHubcloud-architekt/azuread-attack-defense

AzureAD-Attack-Defense

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected.

View Repository
2.5k365273 months agoReviewed by Kitploit

Microsoft Entra ID - Attack and Defense Playbook

This publication is a collection of various common attack scenarios on Microsoft Entra and how they can be mitigated or detected. All of the included scenarios, insights and comments are based on experiences from the contributors during their attack simulations, hands-on or real-world scenarios.

It should be considered a living document, which will be updated as practices progress & changes in attack and defense techniques. We invite identity or security experts from the community to work together on this publication and contribute updates, feedbacks, comments or further additions.

Chapters

  • Password Spray
  • Consent Grant
  • Service Principals in Azure DevOps Pipelines
  • Microsoft Entra Connect Sync Service Account
  • Replay of Primary Refresh (PRT) and other issued tokens
  • Entra ID Security Config Analyzer (EIDSCA)
  • Adversary-in-the-Middle (AiTM) Attacks
  • Microsoft Entra Connect Sync Application-based Authentication
Appendix:
  • Overview of Identity Security Monitoring in Microsoft Cloud
  • How to prevent lateral movement to Entra ID when your Active Directory has fallen

In all chapters, we follow the same guideline on the chapter structure. When reading, you can expect to find:

  • Description of the common attack scenarios in every scenario
  • Detection of the attacks by leveraging Microsoft security stack
  • Mitigation for the attack and instructions how to improve your environment security posture based on the chapter scope
  • Matching of attack scenarios and detection capabilities to Tactics, Techniques & Procedures (TTPs) of MITRE ATT&CK Framework

The following sections contain a short description of each chapter you can find from the 'Entra ID Attack & Defense Playbook'.

Background

The initial idea for creating the ‘Azure AD Attack & Defense Playbook’ came from Thomas Naunheim. Our first Teams call was somewhere in Autumn 2020 where Thomas presented the idea and it was sold immediately.

The first chapter was about the ‘Password Spray’ attack where we focused heavily on the Entra ID Protection (formely known as Azure AD Identity Protection) detection mechanism to detect ‘password spray’ type of attacks. During the first chapter we learned that calendar time for finalizing the research might take significantly longer than expected due to the complexity of the research and different angles on the research. Scoping, like in any project type of work, is extremely important.

Authors


Sami Lamppu

💬 📖

Thomas Naunheim

💬 📖

Contributors and Reviewers


Joosua Santasalo

💬 📖

Markus Pitkäranta

💬 📖

Christopher Brumm

💬 📖

Fabian Bader

💬 📖

Nestori Syynimaa

💬 📖

Robbe Van den Daele

💬 📖

With the latest chapters we have had lucky to have other community members involved to the project such as Joosua Santasalo, Fabian Bader & Christopher Brumm part as a sparring partner and reviewer.

MITRE ATT&CK Framework

MITRE ATT&CK Framework is commonly used for mapping Tactics, Techniques & Procedures (TTPs) for adversary actions and emulating defenses on organizations around the world. In this playbook, we are leveraging the MITRE ATT&CK framework v11 in all of the chapters to map Technics, Tactics & Procedures (TTPs) to the attack scenarios. This would help Blue Teams to build defenses for the corresponding scenarios.

Download Tool