
PowerZure
PowerShell framework to assess Azure security

PowerShell framework to assess Azure security

PowerShell module for Office 365 and Azure log collection

The Azure Active Directory Incident Response PowerShell module provides a number of tools, developed by the Azure Active Directory Product Group in…

PowerShell Module for managing Microsoft Defender Advanced Threat Protection

PowerShell module for administering and auditing Azure AD and Office 365, enabling token manipulation, user enumeration, and security assessments of…

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

A PowerShell script that automates the security assessment of Microsoft 365 environments.

A lightweight PowerShell tool for assessing the security posture of Microsoft Entra ID environments. It helps identify privileged objects, risky…

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

Microsoft Entra Conditional Access Documentation with PowerShell

AzureRT - A Powershell module implementing various Azure Red Team tactics

PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via Microsoft…

PowerShell module for post-breach Azure red teaming, automating token extraction, resource enumeration, and lateral movement within managed identity…

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…

SQLC2 is a PowerShell script for deploying and managing a command and control system that uses SQL Server as both the control server and the agent.

PowerShell tool for enumerating Azure AD users, devices, applications, and domains via Microsoft Graph API, with offline data export capability.

Bash and PowerShell scripts for Azure security assessments, covering IAM privilege escalation, container registry exploitation, Key Vault exposure,…