来源: EvilMist Toolkit - Invoke-EntraEnum.ps1 - https://github.com/Logisek/EvilMist
使用公共 API 发现租户信息。
从 azmap.dev 服务检索租户详细信息。
# Replace DOMAIN with target domain (e.g., example.com)
curl -s "https://azmap.dev/api/tenant?domain=DOMAIN&extract=true"
响应包含: tenantId、displayName、countryCode
检索包括令牌端点在内的 OpenID Connect 配置。
# Replace DOMAIN with target domain
curl -s "https://login.microsoftonline.com/DOMAIN/v2.0/.well-known/openid-configuration"
响应包含: token_endpoint、authorization_endpoint、jwks_uri、issuer
检索域命名空间和联合配置。
# Replace DOMAIN with target domain
curl -s "https://login.microsoftonline.com/getuserrealm.srf?login=enum@DOMAIN&json=1"
响应包含:
NameSpaceType - “Managed”或“Federated”AuthURL - 联合身份验证 URL(如果已联合)CloudInstanceName - 云实例(例如“microsoftonline.com”)FederationBrandName - 组织品牌名称DomainName - 已验证域检查用户是否存在于 Azure AD 中。根据用户存在情况返回不同的代码。
# Replace EMAIL with target email address
curl -s -X POST "https://login.microsoftonline.com/common/GetCredentialType" \
-H "Content-Type: application/json" \
-d '{
"Username": "EMAIL",
"isOtherIdpSupported": true,
"checkPhones": false,
"isRemoteNGCSupported": true,
"isCookieBannerShown": false,
"isFidoSupported": true,
"originalRequest": "",
"country": "US",
"forceotclogin": false,
"isExternalFederationDisallowed": false,
"isRemoteConnectSupported": false,
"federationFlags": 0,
"isSignup": false,
"flowToken": "",
"isAccessPassSupported": true
}'
IfExistsResult 代码:
0 = 用户存在(Azure IdP)1 = 用户不存在2 = 无效请求4 = 服务器错误5 = 用户存在(联合 IdP)6 = 用户存在(外部非 MS IdP)针对 Azure/M365 相关记录的 DNS 查询。可使用 dig、nslookup 或 host 命令。
# Main domain CNAME
dig CNAME DOMAIN
# Autodiscover CNAME
dig CNAME autodiscover.DOMAIN
dig CNAME lyncdiscover.DOMAIN
dig CNAME sip.DOMAIN
dig TXT DOMAIN
dig SRV _ldap._tcp.DOMAIN
dig SRV _kerberos._tcp.DOMAIN
dig SRV _autodiscover._tcp.DOMAIN
dig SRV _sip._tls.DOMAIN
dig SRV _sipfederationtls._tcp.DOMAIN
dig MX DOMAIN
完全不可检测 - 不生成任何审计日志。
通过探测用户的 OneDrive 个人网站 URL 来检查用户是否存在。
# Replace TENANT with tenant name (e.g., example)
# Replace USERPATH with email formatted as: user_domain_com (@ and . replaced with _)
# Example: [email protected] becomes john_doe_example_com
curl -s -o /dev/null -w "%{http_code}" -I \
"https://TENANT-my.sharepoint.com/personal/USERPATH/_layouts/15/onedrive.aspx"
状态代码:
200 = 用户存在,OneDrive 可访问401/403 = 用户存在,访问被拒绝404 = 用户不存在curl -s -o /dev/null -w "%{http_code}" -I \
"https://example-my.sharepoint.com/personal/john_doe_example_com/_layouts/15/onedrive.aspx"
检索包括签名证书和令牌端点在内的联合元数据。
# Replace DOMAIN with target domain
curl -s "https://login.microsoftonline.com/DOMAIN/FederationMetadata/2007-06/FederationMetadata.xml"
响应包含(XML):
检测桌面 SSO(无缝单一登录)是否已启用。
# Replace DOMAIN with target domain
curl -s "https://login.microsoftonline.com/getuserrealm.srf?login=user@DOMAIN&json=1"
查找: DesktopSsoEnabled: true
# Replace TENANT_ID with the tenant GUID
curl -s -o /dev/null -w "%{http_code}" \
"https://autologon.microsoftazuread-sso.com/TENANT_ID/winauth/trust/2005/usernamemixed"
发现与租户关联的 Azure 资源。使用 DNS 解析。
# Replace TENANT with tenant name
# Primary tenant domain
dig A TENANT.onmicrosoft.com
# SharePoint
dig A TENANT.sharepoint.com
# OneDrive
dig A TENANT-my.sharepoint.com
# Azure Blob Storage
dig A TENANT.blob.core.windows.net
# Azure Files
dig A TENANT.file.core.windows.net
# Azure Queue
dig A TENANT.queue.core.windows.net
# Azure Table
dig A TENANT.table.core.windows.net
# Key Vault
dig A TENANT.vault.azure.net
# Azure SQL
dig A TENANT.database.windows.net
# App Service
dig A TENANT.azurewebsites.net
# Kudu/Git Deployment
dig A TENANT.scm.azurewebsites.net
# Cloud Services
dig A TENANT.cloudapp.net
dig A TENANT.cloudapp.azure.com
# Exchange Online Protection
dig A TENANT.mail.protection.outlook.com
# Container Registry
dig A TENANT.azurecr.io
# Redis Cache
dig A TENANT.redis.cache.windows.net
# Service Bus
dig A TENANT.servicebus.windows.net
# Front Door
dig A TENANT.azurefd.net
# Azure AD B2C
dig A TENANT.b2clogin.com
# API Management
dig A TENANT.azure-api.net
# Traffic Manager
dig A TENANT.trafficmanager.net
# HDInsight
dig A TENANT.azurehdinsight.net
# Cosmos DB
dig A TENANT.documents.azure.com
# Cognitive Search
dig A TENANT.search.windows.net
# Cognitive Services
dig A TENANT.cognitiveservices.azure.com
# Common suffixes: dev, prod, staging, test, uat, qa, backup, dr, api, app, web, data
dig A TENANTdev.blob.core.windows.net
dig A TENANTprod.azurewebsites.net
dig A TENANTstaging.vault.azure.net
通过 Autodiscover V2 JSON 端点检查用户是否存在。
# Replace EMAIL with target email address
curl -s -o /dev/null -w "%{http_code}" -L --max-redirs 0 \
"https://autodiscover-s.outlook.com/autodiscover/autodiscover.json?Email=EMAIL&Protocol=Autodiscoverv1"
状态代码:
200 = 用户存在302(重定向)= 用户不存在401/403 = 用户存在(需要认证)用于用户枚举的基于 XML 的旧版 Autodiscover 端点。
# Replace DOMAIN with target domain
# Replace EMAIL with target email address
curl -s -X POST "https://autodiscover.DOMAIN/autodiscover/autodiscover.xml" \
-H "Content-Type: text/xml; charset=utf-8" \
-d '<?xml version="1.0" encoding="utf-8"?>
<Autodiscover xmlns="http://schemas.microsoft.com/exchange/autodiscover/outlook/requestschema/2006">
<Request>
<EMailAddress>EMAIL</EMailAddress>
<AcceptableResponseSchema>http://schemas.microsoft.com/exchange/autodiscover/outlook/responseschema/2006a</AcceptableResponseSchema>
</Request>
</Autodiscover>'
响应指示符:
RedirectAddr = 用户存在RedirectUrl = 可能表示用户存在ErrorCode: InvalidUser = 用户不存在ErrorCode: NoError = 用户存在探测 EWS 端点的暴露情况。
# Office 365 EWS endpoints
curl -s -o /dev/null -w "%{http_code}" \
"https://outlook.office365.com/EWS/Exchange.asmx"
curl -s -o /dev/null -w "%{http_code}" \
"https://outlook.office.com/EWS/Exchange.asmx"
# On-premises/custom domain endpoints
# Replace DOMAIN with target domain
curl -s -o /dev/null -w "%{http_code}" \
"https://DOMAIN/EWS/Exchange.asmx"
curl -s -o /dev/null -w "%{http_code}" \
"https://mail.DOMAIN/EWS/Exchange.asmx"
curl -s -o /dev/null -w "%{http_code}" \
"https://ews.DOMAIN/EWS/Exchange.asmx"
表示可用性的状态代码:
200、301、302、307、308 = 可用401、403 = 可用(需要认证)404 = 不可用发现 SharePoint 和 Teams 站点。
# Replace TENANT with tenant name
# Tenant root
curl -s -o /dev/null -w "%{http_code}" \
"https://TENANT.sharepoint.com"
# OneDrive root
curl -s -o /dev/null -w "%{http_code}" \
"https://TENANT-my.sharepoint.com"
# Common site names to check
# Sites: intranet, portal, hr, finance, it, projects, marketing, sales, support, admin, security, dev
curl -s -o /dev/null -w "%{http_code}" \
"https://TENANT.sharepoint.com/sites/intranet"
curl -s -o /dev/null -w "%{http_code}" \
"https://TENANT.sharepoint.com/sites/portal"