
Microsoft-Sentinel-SecOps
SOC operations content for Microsoft Sentinel, including hunting queries, incident response playbooks, and security event analysis for Azure cloud…

SOC operations content for Microsoft Sentinel, including hunting queries, incident response playbooks, and security event analysis for Azure cloud…

Microsoft Defender XDR KQL detections for RedSun, BlueHammer, UnDefend, and CVE-2026-33825-related Defender abuse behaviors.

CVE-2026-69836 — Unauthenticated RCE via Entra ID deserialization

CLI tool to audit Azure security posture, RBAC, NSGs, storage, identity, and encryption

Exploits CVE-2026-42826 to enumerate and extract sensitive Azure DevOps data via unauthenticated REST API requests: pipeline YAML, variable groups,…

Tooling for assessing an Azure AD tenant state and configuration

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

Automation to assess the state of your M365 tenant against CISA's baselines

Post-exploitation toolkit for Azure AD: fetch/search Microsoft Graph data, swap FOCI refresh tokens, and generate Azure CLI auth files from tokens.

Python script to enumerate valid Microsoft 365 domains, retrieve tenant name, and check for an MDI instance.

Azure AD Password Checker

Repository of attack and defensive information for Business Email Compromise investigations

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

Microsoft Entra ID (Azure AD) Unauthenticated Enumeration

😎 Awesome list of all things related to Microsoft Entra

A collection of scripts for assessing Microsoft Azure security

A forensic reconstruction engine for cloud and identity incident response.

Microsoft Entra Conditional Access Documentation with PowerShell