
Maestro
Post-exploitation tool that abuses Azure Intune/EntraID via C2 agents for PowerShell execution, device queries, and lateral movement without user…

Post-exploitation tool that abuses Azure Intune/EntraID via C2 agents for PowerShell execution, device queries, and lateral movement without user…

CVE-2026-55726 disclosure detailing a publicly listable Azure Blob Storage container exposing Gardyn IoT device logs, including SSIDs, firmware…

CVE-2026-32646 disclosure detailing missing authentication on Gardyn Home Kit administrative device management API endpoint, enabling unauthenticated…

CVE-2026-13768 advisory detailing critical Azure IoT Hub iothubowner credential abuse enabling fleet-wide device enumeration, remote code execution…

Rogue device enrollment tool for Entra ID and Intune MDM. Automates device join, token acquisition, MDM enrollment, and OMA-DM checkin to extract…

PowerShell toolkit for Azure JWT token manipulation, enabling token refresh, switching between service-specific tokens (Graph, Outlook, Teams), and…

Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North…

Device-code phishing server for adversary emulation. Captures Microsoft 365 OAuth tokens via Device Authorization Grant flow. Features relay nodes,…