
Azure
Bash and PowerShell scripts for Azure security assessments, covering IAM privilege escalation, container registry exploitation, Key Vault exposure,…

Bash and PowerShell scripts for Azure security assessments, covering IAM privilege escalation, container registry exploitation, Key Vault exposure,…

The Azure Active Directory Incident Response PowerShell module provides a number of tools, developed by the Azure Active Directory Product Group in…

Read-only PowerShell module for detecting UNC2452 and other threat actor artifacts in Azure AD, auditing federated domains, service principals,…

PowerShell module for administering and auditing Azure AD and Office 365, enabling token manipulation, user enumeration, and security assessments of…

A lightweight PowerShell tool for assessing the security posture of Microsoft Entra ID environments. It helps identify privileged objects, risky…


A fork of the great TokenTactics with support for CAE and token endpoint v2

Kerberos RC4 deprecation: detection, remediation and guidance (CVE-2026-20833)

Automation to assess the state of your M365 tenant against CISA's baselines

A script for advanced discovery of Privileged Accounts - includes Shadow Admins

SkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

CyberArk Security Audit

Tooling for assessing an Azure AD tenant state and configuration

Protect your domain controllers against Zerologon (CVE-2020-1472).

Microsoft Entra Conditional Access Documentation with PowerShell

PowerShell script to enumerate Azure Active Directory access permissions, including role assignments, service principals, and privileged access…

Active Directory password filter featuring breached password checking and custom complexity rules