Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
EvilMist — EvilMist is a collection of scripts and utilities designed to support cloud penetration testing & red teaming. The toolkit helps identify misconfigurations, assess privilege-escalation paths, and simulate attack techniques. EvilMist aims to streamline cloud-focused red-team workflows and improve the overall security posture of cloud infrastructures | Kitploit
Tools/GitHubGitHub/logisek/evilmist
Privilege EscalationReconnaissanceVulnerability AnalysisInformation GatheringPenetration TestingCloud SecurityIdentity & Access Management (IAM)AuthenticationMisconfigurationRed Teaming
GitHub
16122197 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

EvilMist is a collection of scripts and utilities designed to support cloud penetration testing & red teaming. The toolkit helps identify misconfigurations, assess privilege-escalation paths, and simulate attack techniques. EvilMist aims to streamline cloud-focused red-team workflows and improve the overall security posture of cloud infrastructures

logisek/evilmist

EvilMist

View Repository
Share
EvilMist Logo

EvilMist

EvilMist is a collection of scripts and utilities designed to support cloud security configuration audit, cloud penetration testing & cloud red teaming. The toolkit helps identify misconfigurations, assess privilege-escalation paths, and simulate attack techniques. EvilMist aims to streamline cloud-focused red-team workflows and improve the overall security posture of cloud infrastructures


Tools

Unauthenticated Entra ID Enumeration

Unauthenticated Azure/Entra ID enumeration and reconnaissance tool. Performs passive/semi-passive enumeration using publicly accessible APIs and DNS queries without requiring any authentication tokens.

Key Features:

  • No Authentication Required - Works without Azure tokens or credentials
  • Tenant Discovery - Retrieve tenant ID, name, region via azmap.dev and OpenID config
  • Domain Realm Analysis - Identify Managed vs Federated authentication
  • User Existence Checking - Verify email addresses via GetCredentialType API
  • DNS Reconnaissance - Enumerate MX, SPF, TXT, CNAME, SRV, Autodiscover records
  • Port Scanning - Check common Azure ports (HTTPS, LDAP, Kerberos, RDP)
  • Stealth Mode - Configurable delays and jitter to avoid rate limiting
  • Export Options - JSON and CSV export formats
VersionDocumentationFile
PowerShellEntraEnum-PS1.mdscripts/powershell/Invoke-EntraEnum.ps1

Enumerate-EntraUsers

Comprehensive Azure Entra ID (Azure AD) user enumeration and security assessment tool, available in both PowerShell and Python versions.

Key Features:

  • 15+ User Enumeration Methods - Works even when direct /users access is blocked
  • Security Assessment - MFA status, privileged roles, stale accounts, guest users
  • Credential Attack Surface - SSPR, legacy auth, app passwords analysis
  • Conditional Access Analysis - Policy enumeration and gap detection
  • Device & Intune Enumeration - Managed devices, compliance policies
  • Attack Path Analysis - Privilege escalation paths and lateral movement
  • Power Platform - Power Apps and Power Automate flow enumeration
  • Export Options - BloodHound/AzureHound JSON, HTML reports, CSV/JSON
  • Stealth Mode - Configurable delays and jitter to avoid detection
VersionDocumentationFile
PowerShellEntraRecon-PS1.mdscripts/powershell/Invoke-EntraRecon.ps1
PythonEntraRecon-PY.mdscripts/python/entra_recon.py

MFA Security Check

Focused security assessment tool to identify Azure Entra ID users without Multi-Factor Authentication (MFA) enabled. Includes advanced features for shared mailbox detection and sign-in activity analysis..

Key Features:

  • MFA Detection - Identifies users without strong authentication methods
  • Last Sign-In Tracking - Shows last login date/time and activity patterns
  • Shared Mailbox Detection - Automatically identifies and filters shared mailbox accounts
  • Sign-In Capability Check - Determines if accounts can actually authenticate
  • Risk Assessment - Categorizes users by risk level (HIGH/MEDIUM/LOW)
  • Activity Analytics - Sign-in statistics, department breakdowns, stale accounts
  • Matrix View - Compact table format for quick visual scanning
  • Export Options - CSV/JSON with comprehensive user details
  • Stealth Mode - Configurable delays and jitter to avoid detection
VersionDocumentationFile
PowerShellEntraMFACheck-PS1.mdscripts/powershell/Invoke-EntraMFACheck.ps1

Guest Account Enumeration

Comprehensive guest account analysis tool to identify, analyze, and assess the security posture of external users in Azure Entra ID. Essential for guest access governance and security audits.

Key Features:

  • Guest Account Discovery - Enumerate all guest users in the tenant
  • MFA Status Detection - Identify guests without Multi-Factor Authentication
  • Last Sign-In Tracking - Shows login date/time and activity patterns for guests
  • Guest Domain Extraction - Identifies originating organizations of guest users
  • Invite Status Tracking - Shows accepted, pending, or expired invitations
  • Risk Assessment - Categorizes guests by risk level (HIGH/MEDIUM/LOW)
  • Activity Analytics - Sign-in statistics, stale accounts, unused invites
  • Matrix View - Compact table format for quick visual scanning
  • Filtering Options - Show only guests without MFA or include disabled accounts
  • Export Options - CSV/JSON with comprehensive guest details
  • Stealth Mode - Configurable delays and jitter to avoid detection
VersionDocumentationFile
PowerShellEntraGuestCheck-PS1.mdscripts/powershell/Invoke-EntraGuestCheck.ps1

Critical Administrative Access Check

Comprehensive security assessment tool to identify Azure Entra ID users with access to 10 critical administrative applications including PowerShell tools, management portals, core Microsoft 365 services, and privileged identity management. Essential for privileged access governance and administrative tool auditing.

Key Features:

  • Critical Access Discovery - Enumerate users with administrative application access across all tiers
  • Explicit Assignment Focus - Shows users with elevated/administrative access (not basic user access)
  • Default Access Detection - Automatically detects and warns about apps with default access
  • Security-Focused Results - Filters out noise from basic user access to focus on privileged users
  • Multiple Application Coverage - Tracks 10 critical apps: Azure/AD PowerShell, Azure CLI, Graph Tools, M365/Azure Portals, Exchange/SharePoint Online, and PIM
  • MFA Status Detection - Identify privileged users without Multi-Factor Authentication
  • Last Sign-In Tracking - Shows login date/time and activity patterns
  • Assignment Tracking - Shows when users were granted management access
  • Risk Assessment - Categorizes users by risk level (HIGH/MEDIUM/LOW)
  • Activity Analytics - Sign-in statistics, stale accounts, inactive users
  • Matrix View - Compact table format for quick visual scanning
  • Filtering Options - Show only users without MFA or include disabled accounts
  • Export Options - CSV/JSON with comprehensive access details
  • Stealth Mode - Configurable delays and jitter to avoid detection
VersionDocumentationFile
PowerShellEntraAppAccess-PS1.mdscripts/powershell/Invoke-EntraAppAccess.ps1

Quick Start

Script Dispatcher (PowerShell)

Execute any script from the root directory without navigating to subfolders:

# Interactive mode - shows menu to select script
.\Invoke-EvilMist.ps1

# Execute specific script directly
.\Invoke-EvilMist.ps1 -Script EntraRecon -ExportPath "users.csv"

# List all available scripts
.\Invoke-EvilMist.ps1 -List

# Execute with any parameters (all passed through to target script)
.\Invoke-EvilMist.ps1 -Script EntraMFACheck -Matrix -OnlyNoMFA
Download Tool