Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
ツール/GitHubGitHub/jsa2/caoptics
防御ツール構成監査クラウドセキュリティアイデンティティ&アクセス管理 (IAM)認証設定ミスArchived
GitHubjsa2/caoptics

caOptics

CA Optics - Azure AD 条件付きアクセスのギャップ分析ツール

リポジトリを見る
33726212年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

注記

開発優先順位の変更と、コミュニティ活動を他の分野(PoC、他のツール、デモ/プレゼンテーション)に集中させるため、プロジェクトはアーカイブされ、読み取り専用に設定されました。


  • CA Optics - Azure AD 条件付きアクセス ギャップ アナライザー
    • 条件付きアクセスとは
    • 初期テスター向けの注意事項
  • リリースノート
  • ドキュメント
    • ギャップの例
    • 順列の生成
    • 前提条件
    • 重要
    • 説明 - Conditional Access ギャップ アナライザー
      • 既存ツールとの比較
    • スコープ
    • 主観的な設計
      • 設計上の決定
        • プラットフォームのルックアップ
        • ルックアップの違い
        • グループの入れ子
    • パラメーター
      • launch.json からパラメーターを指定する(VSCode でのデバッグ)?
    • ツールの実行
    • レポートの表示
    • トラブルシューティング
  • コントリビューション

CA Optics - Azure AD 条件付きアクセス ギャップ アナライザー

Azure AD Conditional Access Gap Analyzer は、複雑な Azure Active Directory 条件付きアクセス ポリシー構成内に存在する可能性のあるギャップをスキャンするためのソリューションです。

条件付きアクセスとは

条件付きアクセスに初めて触れる場合は、次の Microsoft の記事を確認することをお勧めします: https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/overview


初期テスター向けの注意事項


このツールを実行するためのワンライナー:(これだけを読む予定で、インストールが完了している場合)

node ./ca/main.js --mapping --skipObjectId=259fcf40-ff7c-4625-9b78-cd11793f161f --clearPolicyCache --clearTokenCache --clearMappingCache


前提条件を完了し、この README ファイルを読んだら、以下を検討してください:

  1. reportOnly ポリシーは終了条件として考慮されません: 参照: scope

  2. 各スキャンを --clearPolicyCache 付きで実行してください

  3. ポリシーに関連するグループ/ユーザーに変更を加えた場合は、各スキャンを --clearMappingCache 付きで実行してください

  4. ユーザーとアプリを対象とするポリシーのみがスコープに含まれます(これは最も一般的なスコープですが、たとえばセキュリティ登録ポリシーは評価されないことを意味します) 参照: scope

  5. まずテスト環境から始めて、ツールの仕組みについて経験を積み、期待値を設定できるようにしてください

  6. ポリシーから除外されている既知のグループまたはユーザーがいる場合は、除外を確認したい場合を除き、--skipObjectIds でスキャンから除外するオブジェクトを定義してください

  7. 複数の環境でスキャンを実行する場合は、新しいスキャンを実行する前にログインとキャッシュを削除してください

参照:parameters - AZ CLI をインストールしている場合は、az account clear で AZ CLI のキャッシュをクリアしてから、スキャン予定の環境に対して az login で新しいログインを実行してください

参照 その他の重要な注意事項


リリースノート

Release notes: 0.7.1
- Updated depedencies and report text outputs 
Release notes: 0.7
- Uses beta endpoint now by default, --expand option now expands the results to report regardless of the use of --allTerminations
Release notes: 0.6.9
- using --expand=9c06d103-f5b0-4404-bb25-aec4636912cd,47087cd3-64e9-470b-980a-5662f498e016 and expand 10 group members to for separate inspection.
Release notes: 0.6.8
- When you update policy with any guest conditions in GUI that policy will be only available from the beta endpoint after the update (during preview). 
- This update brings normalization for policies that are transfered to beta endpoint due to this behavior. 
- The policy will be evaluated like the previous guest conditions, as long as the following conditions are included "internalGuest,b2bCollaborationGuest,b2bCollaborationMember" and no tenants are excluded from the policy. In order to evaluate transferred policies, 
- use '--allowPreviewPolicies' when running CaOptics to account for this behavior

Release notes: 0.6.6-7 beta
- Allow use of different login endpoints for login and graph with params: --altLogin --altGraph
- Allow use of custom filtering for policies (this only recommended, when the policies do not adhere to expected schema)

Release notes: 0.6.5 beta
- Added counter to reporting when high number of permutations is also added to report (default is to add only unterminated)
- Minor code fixes changing <var> to <let> 
- Report filename now includes day, month, year and tenantId e.g. report_day_4_month_9_year_2022-tenant_48f55450-183a-45d6-a9ce-68f3cbc68947.csv

Release notes: 0.6.4 beta
- Get more groups per single call (less batching)
- Fix race condition detected when generally using for await loops 
- Enclose values with "" between delimitters (CSV)

Release notes: 0.6.3 beta
- Optimizations to way the mapped objects are handled. 
  - Mapped objects are cached. You can recreate the object mapping by using parama 'clearMappingCache'
  - Lookup keys will start from 'user/group/role' conditions always first
  - Added possibility to populate usermap with random UUID's to test for performance impact (this just debug option, and not really something that would be in non-beta versions)

Release notes: 0.6.2 beta
- Separated cache params into separate functions -> (clearTokenCache and ClearPolicyCache)
- Added possibility of running pre-optimized algorithm on permutations with param --aggressive (High memory consumption, only here for A/B testing)
- merge completed.

Release notes: 0.6.1 beta 
- Basic version of CSV reporting added
- Streamlined permutation generation to ensure essential permutations are generated, and some permutations are are terminated earlier on the lookups

Release notes: 0.6 beta (first non "silent" release)
- App displayNames added to MD report. Object type added to the user type

Release notes: 0.5.2,0.5.1,0.5 beta  (see previous branches for release notes)


ドキュメント

ギャップの例

クロスポリシー検出の例

❌ 値が 0 の順列は、その特定の条件の組み合わせに対して終了したポリシーがないことを意味します。

ポリシー終了数ルックアップ
All0Applications:88cc92be-d474-4d95-a57d-7b3ef701f510 -> Locations:finland -> users:GuestsOrExternalUsers
All0Applications:88cc92be-d474-4d95-a57d-7b3ef701f510 -> Locations:finland -> users:Jane Doe
All0Applications:88cc92be-d474-4d95-a57d-7b3ef701f510 -> Locations:finland -> users:John Doe

✅ 検出の詳細な説明は docs/example.md でお読みください


順列の生成

順列は getPol2.js によって生成されます

  • 仕組み: すべての条件に対して再帰的検索が実行され、その後、条件は一意の順列の下に配置されます

順列は JSON Crack サービスで視覚化できます:

(視覚化: https://jsoncrack.com/)

前提条件

ランタイム

  • Node.JS 14 LTS (Linux) (Linux へのインストール)
  • Node.JS 16 LTS (Windows) (Windows へのインストール)
ツールをダウンロード