
ScubaGear
Automation to assess the state of your M365 tenant against CISA's baselines

Automation to assess the state of your M365 tenant against CISA's baselines

Free email OSINT tool, 2500+ platforms, identity clustering, breach detection. No API keys required. pip install mailaccess

A fork of the great TokenTactics with support for CAE and token endpoint v2

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

290+ Automated checks across 14 compliance frameworks, interactive HTML report, no data leaves your machine.

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

Repository of attack and defensive information for Business Email Compromise investigations

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

tool for requesting Entra ID's P2P certificate and authenticating to a remote Entra joinned devices with it

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.