Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
Azure-AD-Password-Checker — Azure AD 비밀번호 검사기 | Kitploit
도구/GitHubGitHub/quahac/azure-ad-password-checker
Defensive ToolsConfiguration AuditingCloud SecurityIdentity & Access Management (IAM)AuthenticationRed Teaming
GitHubquahac/azure-ad-password-checker

Azure-AD-Password-Checker

Azure AD 비밀번호 검사기

저장소 보기
866181년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

Azure AD 비밀번호 검사기

Azure AD 환경에서 특별한 권한 없이도 사용자가 MFA(다단계 인증)를 비활성화했는지 확인할 수 있습니다. 이는 계정 생성 날짜와 마지막 비밀번호 변경 날짜를 분석하여 확인할 수 있습니다.

계정의 생성 날짜와 시간이 마지막 비밀번호 변경 날짜와 시간과 일치한다면, 계정 생성 이후 사람의 상호작용이 없었고 사용자가 MFA(다단계 인증)를 활성화하거나 비밀번호를 변경하지 못했음을 나타낼 수 있습니다. 또한 비밀번호 변경 날짜가 생성 날짜보다 이른 것과 같은 다른 '이상 징후'도 있습니다. 이는 사용자가 아직 생성되지 않았기 때문에 MFA(다단계 인증)를 활성화할 수 없었음을 시사합니다!

2023-10-16 업데이트:

  • 두 사용자가 정확히 같은 시간에 비밀번호를 변경할 가능성은 얼마나 될까요? 이는 또 다른 MFA 이상 징후로 간주될 수 있습니다. 파란색으로 표시되며 (나타나는 횟수)로 표시됩니다.

2024-02-18 업데이트:

  • MFA 이상 징후 사용자를 파일로 출력
  • 비밀번호 변경 없이도 전화 통화나 SMS를 통해 MFA(다단계 인증)를 활성화할 수 있습니다. 그러나 사용자 계정에 전화번호가 등록되어 있지 않으면 관리자는 전화 또는 문자 메시지 확인 옵션을 활성화할 수 없습니다. 이는 사용자가 계정 생성 시 또는 로그인 중에 전화번호를 인증할 수 없음을 의미합니다. 전화번호 인증이 없으면 MFA가 구성되지 않은 계정을 더 쉽게 식별할 수 있습니다. 이를 해결하기 위해 전화번호가 없는 계정은 연한 파란색으로 표시되고 (phone numbers: x)로 주석 처리됩니다.
    참조: Microsoft/Azure SMS 또는 전화 통화 - 첫 번째 가입 또는 로그인 시 사용자는 전화번호를 제공하고 인증해야 합니다. 이후 로그인 시 사용자는 Send Code 또는 Call Me 옵션 중 하나를 선택하라는 메시지가 표시됩니다.

이 정보는 레드 팀과 블루 팀 모두를 위해 설계된 잠재적인 보안 위험을 식별하는 데 유용할 수 있습니다.

이 도구에는 --code-javascript 옵션을 사용하여 추출한 roadrecon 데이터베이스 파일 또는 JSON 파일이 필요합니다. Roadrecon 도구는 dirkjanm이 개발했으며 github https://github.com/dirkjanm/ROADtools 에서 다운로드하거나 pip install roadrecon 명령으로 설치할 수 있습니다.

사용 방법:

python3 azurepwchecker.py
usage: azurepwchecker.py [-h] [--roadrecon-dump] [--roadrecon-dump-mfa] [-d DB] [-m] [-l] [-ll] [-lll] [-la] [-lo]
                         [-ji JSON_INPUT] [-c]

Azure AD Password Checker - This is a parser for generated JSON file or the roadrecon database file designed for use by both red and blue teams. 
Database can be created when using --code-javascript option to extract 'merged_users.json' file with be created to later input this file with --json-input argument.
And roadrecon generated roadrecon.db file can be used! roadrecon is developed by https://github.com/dirkjanm credits to him!

options:
  -h, --help            show this help message and exit
  -d DB, --db DB        Specify the path to the 'roadrecon.db' database file, default is this location
  -m, --mfa-list        User Accounts without MFA (No privileged user required)! This argument helps identify user
                        accounts that have not enabled Multi-Factor Authentication (MFA). If an account's creation
                        date and time match its last password change date and time, it may indicate that no human
                        interaction has occurred since the account was created, and the user has not been able to
                        enable MFA or change their password. And there are other 'anomalies' such as the password
                        change date being older than the creation date. This suggests also that Multi-Factor
                        Authentication (MFA) couldn't be enabled because the User wasn't created yet! :-]
  -mo OUTFILE, --outfile OUTFILE
                        Output users with MFA anomalies to file
  -l, --pw-month        User accounts that had their passwords changed last month
  -ll, --pw-year        User accounts that had their passwords changed last year
  -lll, --pw-older      User accounts that haven't changed their passwords in a long time, oldest first
  -la, --admin          User accounts that are members of 'Admin' named groups, including 'Global Reader'
  -lo, --out-of-hours   User password change that occurred outside of office hours, specifically between 5:00 PM
                        (17:00) and 8:00 AM (08:00) on weekdays, as well as on Saturdays and Sundays
  -ji JSON_INPUT, --json-input JSON_INPUT
                        Provide the JSON file imported from your web browser's console using JavaScript. For
                        'createdDateTime' and 'lastPasswordChange' details, ensure you download the JSON output using
                        the '--code-javascript' option.
  -c, --code-javascript
                        Perform extraction even if 'azurepwchecker.py' or 'roadrecon' is unavailable. This script
                        enables extraction through the JavaScript console of a web browser. To proceed, ensure you
                        have a valid account to log in at https://portal.azure.com/#view/Microsoft_AAD_UsersAndTenants
                        /UserManagementMenuBlade/~/AllUsers or an active session on a computer. Copy and paste the
                        provided JavaScript code into the browser's console. Once the session is validated and you
                        have the necessary permissions, a JSON file named 'merged_users.json' will be generated. You
                        can then import it using the following command as example: 'azurepwchecker.py --json-input
                        merged_users.json -m'
  -v, --version         show program's version number and exit
  
run roadrecon first:
  (Run the following command to install the tool "pip install roadrecon)"

  --roadrecon-dump      "roadrecon dump" command or do it with roadrecon
  --roadrecon-dump-mfa  "roadrecon dump --mfa" command (requires privileged access) or do it with roadrecon

roadrecon이 없는 경우 > azurepwchecker.py --code-javascript 명령을 실행하고 복사하거나 폴더에 js 파일을 생성하세요:

제공된 스크립트를 사용하여 사용자 목록과 계정 정보를 검색하려면 다음 단계를 따르세요.

  1. Azure Portal에 로그인

    • https://portal.azure.com 으로 이동하여 유효한 계정으로 로그인하세요.
  2. 사용자 관리에 접근

    • Azure Portal에서 사용자 관리 로 이동하세요.
  3. 개발자 도구 열기

    • 웹 브라우저에서 F12를 눌러 개발자 도구를 엽니다.
  4. 스크립트 실행

    • 제공된 스크립트를 복사하여 붙여넣으세요.
  5. UsersList 및 UserInfo 검색

    • 스크립트는 생성 날짜와 마지막 비밀번호 변경을 포함한 사용자 정보와 함께 UsersList를 가져옵니다.
  6. 병합된 사용자 정보 다운로드

    • 스크립트 실행이 완료되면 다운로드 폴더를 확인하세요. 모든 것이 정상적으로 진행되면 merged_users.json 파일이 생성됩니다.
  7. Azure AD 비밀번호 검사기에서 실행

    • azurepwchecker.py --json-input merged_users.json

예시 보기:

https://github.com/quahac/Azure-AD-Password-Checker/assets/49560894/0fd77e2c-068e-4aef-aafd-c5ec23db7385

소개 보기:

https://user-images.githubusercontent.com/49560894/233073626-d1ccc173-c3cf-4751-878b-e8f0c65e6c0a.mp4

2023-10-16 업데이트:

double_lastpasswordchangedatetime

Azure Portal에서 사용자 목록을 생성한 다음 azurepwchecker.py --json-input merged_users.json 명령으로 가져오려면 --code-javascript 인수를 사용하는 방법:

2024-02-13 업데이트:

@dafthack가 개발한 GraphRunner의 수정 버전을 업로드했습니다. 이 수정된 버전에는 "피해자" 기기에서 HAR 파일을 직접 읽을 수 있는 새로운 기능이 추가되었습니다. 이 새로운 기능은 다양한 권한 또는 범위에 접근하기 위한 액세스 토큰을 확인하고 검사하는 데 도움이 됩니다. 또한 액세스 토큰이 만료된 경우 이 버전에서는 새 액세스 토큰을 생성하기 위해 리프레시 토큰을 사용할 수 있습니다. 이 과정은 시간에 민감하지만, 이미 Office365 환경에 로그인한 상태라면 HAR 파일에 있는 세션 토큰만 필요하므로 사용자 이름과 비밀번호가 필요 없어집니다.

코드가 다소 정리되지 않아 보일 수 있다는 점을 양해 부탁드립니다. 제 전문 분야가 주로 JavaScript는 아니기 때문에 코드를 정리하는 것보다 새로운 기능을 추가하는 데 중점을 두었습니다.

  1. 웹 브라우저에서 제공되는 개발자 도구를 사용하여 HAR 파일을 다운로드할 수 있습니다. 대부분의 브라우저에서는 F12를 눌러 개발자 도구를 연 다음 '네트워크' 탭으로 이동하여 웹페이지를 새로 고친 후 HAR 파일을 저장하면 됩니다: video

  2. 제공된 인터페이스를 통해 HAR 파일을 업로드하세요. 업로드가 완료되면 다양한 액세스 토큰을 탐색하여 범위를 포함한 세션 세부 정보를 분석할 수 있습니다. 빨간색으로 표시된 토큰은 만료되었음을 나타냅니다. GraphRunner는 필요할 때 리프레시 토큰을 사용하여 새롭고 유효한 액세스 토큰을 생성하는 기능도 지원합니다: video

  3. 전체 사용자 데이터를 JSON 파일로 다운로드하고, 계정의 MFA 이상 징후를 감지하며, 이러한 이상 징후 목록을 다운로드할 수 있는 기능이 추가되었습니다: video

도구 다운로드