
awesome-cybersecurity-blueteam
💻🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.

💻🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

AAD related enumeration in Nim

Azure AD Password Checker

Repository of attack and defensive information for Business Email Compromise investigations

Converts Active Directory Explorer snapshot (.dat) files into BloodHound CE JSON archives for graph-based AD attack-path analysis and reconnaissance.

Salesforce object access auditor

Salesforce Policy Deviation Checker

BloodHound OpenGraph collector for GitHub that maps organization structure, permissions, and cross-cloud attack paths into a navigable graph for…

Monitor changes in Active Directory with replication metadata

A lightweight PowerShell tool for assessing the security posture of Microsoft Entra ID environments. It helps identify privileged objects, risky…

EvilMist is a collection of scripts and utilities designed to support cloud penetration testing & red teaming. The toolkit helps identify…

Creating attacks paths across management and data planes

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

SkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS

PowerShell module for administering and auditing Azure AD and Office 365, enabling token manipulation, user enumeration, and security assessments of…


AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…