
ScubaGear
Automation to assess the state of your M365 tenant against CISA's baselines

Automation to assess the state of your M365 tenant against CISA's baselines

A tool for checking if MFA is enabled on multiple Microsoft Services

PowerShell module for administering and auditing Azure AD and Office 365, enabling token manipulation, user enumeration, and security assessments of…

SkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

A PowerShell script that automates the security assessment of Microsoft 365 environments.


A lightweight PowerShell tool for assessing the security posture of Microsoft Entra ID environments. It helps identify privileged objects, risky…

The Azure Active Directory Incident Response PowerShell module provides a number of tools, developed by the Azure Active Directory Product Group in…

A fork of the great TokenTactics with support for CAE and token endpoint v2

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

Abusing Azure services over C2

AzureRT - A Powershell module implementing various Azure Red Team tactics


PowerShell tool for enumerating Azure AD users, devices, applications, and domains via Microsoft Graph API, with offline data export capability.

PowerShell module for post-breach Azure red teaming, automating token extraction, resource enumeration, and lateral movement within managed identity…

CyberArk Security Audit