Skip to content
KitploitKITPLOIT
ツールブログ
Log in
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
AzureADEnumeration — Microsoft Entra ID (Azure AD) 未認証列挙 | Kitploit
ツール/GitHubGitHub/logisek/azureadenumeration
クラウドインフラストラクチャセキュリティOSINT (オープンソースインテリジェンス)偵察情報収集ペネトレーションテストクラウドセキュリティサブドメイン列挙メールセキュリティDNS分析
GitHublogisek/azureadenumeration

AzureADEnumeration

Microsoft Entra ID (Azure AD) 未認証列挙

795287ヶ月前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
リポジトリを見る

Microsoft Entra ID (Azure AD) 未認証列挙

ソース: EvilMist Toolkit - Invoke-EntraEnum.ps1 - https://github.com/Logisek/EvilMist


1. テナント検出 (-TenantInfo)

公開 API を使用してテナント情報を検出します。

1.1 azmap.dev API

azmap.dev サービスからテナントの詳細を取得します。

# Replace DOMAIN with target domain (e.g., example.com)
curl -s "https://azmap.dev/api/tenant?domain=DOMAIN&extract=true"

レスポンスに含まれるもの: tenantId、displayName、countryCode

1.2 OpenID 構成

トークンエンドポイントを含む OpenID Connect 構成を取得します。

# Replace DOMAIN with target domain
curl -s "https://login.microsoftonline.com/DOMAIN/v2.0/.well-known/openid-configuration"

レスポンスに含まれるもの: token_endpoint、authorization_endpoint、jwks_uri、issuer


2. ドメインレルム情報 (-DomainRealm)

ドメインの名前空間とフェデレーション構成を取得します。

# Replace DOMAIN with target domain
curl -s "https://login.microsoftonline.com/getuserrealm.srf?login=enum@DOMAIN&json=1"

レスポンスに含まれるもの:

  • NameSpaceType - "Managed" または "Federated"
  • AuthURL - フェデレーション認証 URL(フェデレーションの場合)
  • CloudInstanceName - クラウドインスタンス(例:"microsoftonline.com")
  • FederationBrandName - 組織のブランド名
  • DomainName - 検証済みドメイン

3. GetCredentialType によるユーザー列挙 (-UserEnum)

Azure AD にユーザーが存在するかどうかを確認します。ユーザーの存在に基づいて異なるコードを返します。

# Replace EMAIL with target email address
curl -s -X POST "https://login.microsoftonline.com/common/GetCredentialType" \
  -H "Content-Type: application/json" \
  -d '{
    "Username": "EMAIL",
    "isOtherIdpSupported": true,
    "checkPhones": false,
    "isRemoteNGCSupported": true,
    "isCookieBannerShown": false,
    "isFidoSupported": true,
    "originalRequest": "",
    "country": "US",
    "forceotclogin": false,
    "isExternalFederationDisallowed": false,
    "isRemoteConnectSupported": false,
    "federationFlags": 0,
    "isSignup": false,
    "flowToken": "",
    "isAccessPassSupported": true
  }'

IfExistsResult コード:

  • 0 = ユーザーが存在(Azure IdP)
  • 1 = ユーザーは存在しない
  • 2 = 無効なリクエスト
  • 4 = サーバーエラー
  • 5 = ユーザーが存在(フェデレーション IdP)
  • 6 = ユーザーが存在(外部の非 Microsoft IdP)

4. DNS 偵察 (-DnsEnum)

Azure/M365 関連レコードの DNS クエリを実行します。dig、nslookup、または host コマンドを使用します。

4.1 CNAME レコード

# Main domain CNAME
dig CNAME DOMAIN

# Autodiscover CNAME
dig CNAME autodiscover.DOMAIN
dig CNAME lyncdiscover.DOMAIN
dig CNAME sip.DOMAIN

4.2 TXT/SPF レコード

dig TXT DOMAIN

4.3 SRV レコード

dig SRV _ldap._tcp.DOMAIN
dig SRV _kerberos._tcp.DOMAIN
dig SRV _autodiscover._tcp.DOMAIN
dig SRV _sip._tls.DOMAIN
dig SRV _sipfederationtls._tcp.DOMAIN

4.4 MX レコード

dig MX DOMAIN

5. OneDrive ユーザー列挙 (-OneDriveEnum)

完全に検知不可能 - 監査ログは生成されません。

OneDrive 個人サイトの URL をプローブすることで、ユーザーの存在を確認します。

# Replace TENANT with tenant name (e.g., example)
# Replace USERPATH with email formatted as: user_domain_com (@ and . replaced with _)
# Example: [email protected] becomes john_doe_example_com

curl -s -o /dev/null -w "%{http_code}" -I \
  "https://TENANT-my.sharepoint.com/personal/USERPATH/_layouts/15/onedrive.aspx"

ステータスコード:

  • 200 = ユーザーが存在、OneDrive にアクセス可能
  • 401/403 = ユーザーが存在、アクセス拒否
  • 404 = ユーザーは存在しない

ユーザー [email protected] の例:

curl -s -o /dev/null -w "%{http_code}" -I \
  "https://example-my.sharepoint.com/personal/john_doe_example_com/_layouts/15/onedrive.aspx"

6. フェデレーションメタデータ (-FederationMeta)

署名証明書とトークンエンドポイントを含むフェデレーションメタデータを取得します。

# Replace DOMAIN with target domain
curl -s "https://login.microsoftonline.com/DOMAIN/FederationMetadata/2007-06/FederationMetadata.xml"

レスポンスに含まれるもの (XML):

  • エンティティ ID
  • X509 署名証明書
  • トークンエンドポイント
  • NameID 形式
  • クレームタイプ
  • ADFS サーバー情報(フェデレーションの場合)

7. シームレス SSO 検出 (-SeamlessSSO)

デスクトップ SSO(シームレス シングル サインオン)が有効かどうかを検出します。

7.1 SSO 構成の確認

# Replace DOMAIN with target domain
curl -s "https://login.microsoftonline.com/getuserrealm.srf?login=user@DOMAIN&json=1"

確認する項目: DesktopSsoEnabled: true

7.2 自動ログオンエンドポイントのテスト(SSO が有効な場合)

# Replace TENANT_ID with the tenant GUID
curl -s -o /dev/null -w "%{http_code}" \
  "https://autologon.microsoftazuread-sso.com/TENANT_ID/winauth/trust/2005/usernamemixed"

8. Azure サブドメイン列挙 (-SubdomainEnum)

テナントに関連付けられた Azure リソースを検出します。DNS 解決を使用します。

確認すべき主要な Azure サブドメイン:

# Replace TENANT with tenant name

# Primary tenant domain
dig A TENANT.onmicrosoft.com

# SharePoint
dig A TENANT.sharepoint.com

# OneDrive
dig A TENANT-my.sharepoint.com

# Azure Blob Storage
dig A TENANT.blob.core.windows.net

# Azure Files
dig A TENANT.file.core.windows.net

# Azure Queue
dig A TENANT.queue.core.windows.net

# Azure Table
dig A TENANT.table.core.windows.net

# Key Vault
dig A TENANT.vault.azure.net

# Azure SQL
dig A TENANT.database.windows.net

# App Service
dig A TENANT.azurewebsites.net

# Kudu/Git Deployment
dig A TENANT.scm.azurewebsites.net

# Cloud Services
dig A TENANT.cloudapp.net
dig A TENANT.cloudapp.azure.com

# Exchange Online Protection
dig A TENANT.mail.protection.outlook.com

# Container Registry
dig A TENANT.azurecr.io

# Redis Cache
dig A TENANT.redis.cache.windows.net

# Service Bus
dig A TENANT.servicebus.windows.net

# Front Door
dig A TENANT.azurefd.net

# Azure AD B2C
dig A TENANT.b2clogin.com

# API Management
dig A TENANT.azure-api.net

# Traffic Manager
dig A TENANT.trafficmanager.net

# HDInsight
dig A TENANT.azurehdinsight.net

# Cosmos DB
dig A TENANT.documents.azure.com

# Cognitive Search
dig A TENANT.search.windows.net

# Cognitive Services
dig A TENANT.cognitiveservices.azure.com

パーミュテーションの例:

# Common suffixes: dev, prod, staging, test, uat, qa, backup, dr, api, app, web, data
dig A TENANTdev.blob.core.windows.net
dig A TENANTprod.azurewebsites.net
dig A TENANTstaging.vault.azure.net

9. Autodiscover V2 列挙 (-AutodiscoverEnum)

Autodiscover V2 の JSON エンドポイントを介してユーザーの存在を確認します。

# Replace EMAIL with target email address
curl -s -o /dev/null -w "%{http_code}" -L --max-redirs 0 \
  "https://autodiscover-s.outlook.com/autodiscover/autodiscover.json?Email=EMAIL&Protocol=Autodiscoverv1"

ステータスコード:

  • 200 = ユーザーが存在
  • 302(リダイレクト)= ユーザーは存在しない
  • 401/403 = ユーザーが存在(認証が必要)

10. Autodiscover V1 列挙 (-AutodiscoverV1Enum)

ユーザー列挙のためのレガシー XML ベースの Autodiscover エンドポイントです。

# Replace DOMAIN with target domain
# Replace EMAIL with target email address

curl -s -X POST "https://autodiscover.DOMAIN/autodiscover/autodiscover.xml" \
  -H "Content-Type: text/xml; charset=utf-8" \
  -d '<?xml version="1.0" encoding="utf-8"?>
<Autodiscover xmlns="http://schemas.microsoft.com/exchange/autodiscover/outlook/requestschema/2006">
  <Request>
    <EMailAddress>EMAIL</EMailAddress>
    <AcceptableResponseSchema>http://schemas.microsoft.com/exchange/autodiscover/outlook/responseschema/2006a</AcceptableResponseSchema>
  </Request>
</Autodiscover>'

レスポンスの指標:

  • レスポンス内の RedirectAddr = ユーザーが存在
  • レスポンス内の RedirectUrl = 存在を示す可能性あり
  • ErrorCode: InvalidUser = ユーザーは存在しない
  • ErrorCode: NoError = ユーザーが存在

11. Exchange Web サービス (EWS) プローブ (-EwsProbe)

公開状況を確認するために EWS エンドポイントをプローブします。

# Office 365 EWS endpoints
curl -s -o /dev/null -w "%{http_code}" \
  "https://outlook.office365.com/EWS/Exchange.asmx"

curl -s -o /dev/null -w "%{http_code}" \
  "https://outlook.office.com/EWS/Exchange.asmx"

# On-premises/custom domain endpoints
# Replace DOMAIN with target domain
curl -s -o /dev/null -w "%{http_code}" \
  "https://DOMAIN/EWS/Exchange.asmx"

curl -s -o /dev/null -w "%{http_code}" \
  "https://mail.DOMAIN/EWS/Exchange.asmx"

curl -s -o /dev/null -w "%{http_code}" \
  "https://ews.DOMAIN/EWS/Exchange.asmx"

利用可能性を示すステータスコード:

  • 200、301、302、307、308 = 利用可能
  • 401、403 = 利用可能(認証が必要)
  • 404 = 利用不可

12. SharePoint/Teams 検出 (-SharePointEnum)

SharePoint および Teams サイトを検出します。

# Replace TENANT with tenant name
ツールをダウンロード