
AzureAD-Attack-Defense
This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they…

Automation to assess the state of your M365 tenant against CISA's baselines

Free email OSINT tool, 2500+ platforms, identity clustering, breach detection. No API keys required. pip install mailaccess

A fork of the great TokenTactics with support for CAE and token endpoint v2

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

Repository of attack and defensive information for Business Email Compromise investigations

290+ Automated checks across 14 compliance frameworks, interactive HTML report, no data leaves your machine.

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

tool for requesting Entra ID's P2P certificate and authenticating to a remote Entra joinned devices with it

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…