
BloodHound
Six Degrees of Domain Admin

Six Degrees of Domain Admin

A collection of Azure AD/Entra tools for offensive and defensive security purposes

PowerShell module for administering and auditing Azure AD and Office 365, enabling token manipulation, user enumeration, and security assessments of…

Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they…

Free email OSINT tool, 2500+ platforms, identity clustering, breach detection. No API keys required. pip install mailaccess

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

SkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS

A lightweight PowerShell tool for assessing the security posture of Microsoft Entra ID environments. It helps identify privileged objects, risky…


Tooling for assessing an Azure AD tenant state and configuration

In-depth ldap enumeration utility

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

AWS Identity and Access Management Visualizer and Anomaly Finder

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

BloodHound OpenGraph collector for GitHub that maps organization structure, permissions, and cross-cloud attack paths into a navigable graph for…

EvilMist is a collection of scripts and utilities designed to support cloud penetration testing & red teaming. The toolkit helps identify…

Entra ID user enumeration and auth method discovery via the public GetCredentialType API