Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
AzureADEnumeration — Microsoft Entra ID (Azure AD) 未认证枚举 | Kitploit
工具/GitHubGitHub/logisek/azureadenumeration
云基础设施安全OSINT (开源情报)侦察信息收集渗透测试云安全子域名枚举电子邮件安全DNS 分析
GitHublogisek/azureadenumeration

AzureADEnumeration

Microsoft Entra ID (Azure AD) 未认证枚举

795297个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库

Microsoft Entra ID(Azure AD)未认证枚举

来源: EvilMist Toolkit - Invoke-EntraEnum.ps1 - https://github.com/Logisek/EvilMist


1. 租户发现(-TenantInfo)

使用公共 API 发现租户信息。

1.1 azmap.dev API

从 azmap.dev 服务检索租户详细信息。

# Replace DOMAIN with target domain (e.g., example.com)
curl -s "https://azmap.dev/api/tenant?domain=DOMAIN&extract=true"

响应包含: tenantId、displayName、countryCode

1.2 OpenID 配置

检索包括令牌端点在内的 OpenID Connect 配置。

# Replace DOMAIN with target domain
curl -s "https://login.microsoftonline.com/DOMAIN/v2.0/.well-known/openid-configuration"

响应包含: token_endpoint、authorization_endpoint、jwks_uri、issuer


2. 域领域信息(-DomainRealm)

检索域命名空间和联合配置。

# Replace DOMAIN with target domain
curl -s "https://login.microsoftonline.com/getuserrealm.srf?login=enum@DOMAIN&json=1"

响应包含:

  • NameSpaceType - “Managed”或“Federated”
  • AuthURL - 联合身份验证 URL(如果已联合)
  • CloudInstanceName - 云实例(例如“microsoftonline.com”)
  • FederationBrandName - 组织品牌名称
  • DomainName - 已验证域

3. 通过 GetCredentialType 进行用户枚举(-UserEnum)

检查用户是否存在于 Azure AD 中。根据用户存在情况返回不同的代码。

# Replace EMAIL with target email address
curl -s -X POST "https://login.microsoftonline.com/common/GetCredentialType" \
  -H "Content-Type: application/json" \
  -d '{
    "Username": "EMAIL",
    "isOtherIdpSupported": true,
    "checkPhones": false,
    "isRemoteNGCSupported": true,
    "isCookieBannerShown": false,
    "isFidoSupported": true,
    "originalRequest": "",
    "country": "US",
    "forceotclogin": false,
    "isExternalFederationDisallowed": false,
    "isRemoteConnectSupported": false,
    "federationFlags": 0,
    "isSignup": false,
    "flowToken": "",
    "isAccessPassSupported": true
  }'

IfExistsResult 代码:

  • 0 = 用户存在(Azure IdP)
  • 1 = 用户不存在
  • 2 = 无效请求
  • 4 = 服务器错误
  • 5 = 用户存在(联合 IdP)
  • 6 = 用户存在(外部非 MS IdP)

4. DNS 侦察(-DnsEnum)

针对 Azure/M365 相关记录的 DNS 查询。可使用 dig、nslookup 或 host 命令。

4.1 CNAME 记录

# Main domain CNAME
dig CNAME DOMAIN

# Autodiscover CNAME
dig CNAME autodiscover.DOMAIN
dig CNAME lyncdiscover.DOMAIN
dig CNAME sip.DOMAIN

4.2 TXT/SPF 记录

dig TXT DOMAIN

4.3 SRV 记录

dig SRV _ldap._tcp.DOMAIN
dig SRV _kerberos._tcp.DOMAIN
dig SRV _autodiscover._tcp.DOMAIN
dig SRV _sip._tls.DOMAIN
dig SRV _sipfederationtls._tcp.DOMAIN

4.4 MX 记录

dig MX DOMAIN

5. OneDrive 用户枚举(-OneDriveEnum)

完全不可检测 - 不生成任何审计日志。

通过探测用户的 OneDrive 个人网站 URL 来检查用户是否存在。

# Replace TENANT with tenant name (e.g., example)
# Replace USERPATH with email formatted as: user_domain_com (@ and . replaced with _)
# Example: [email protected] becomes john_doe_example_com

curl -s -o /dev/null -w "%{http_code}" -I \
  "https://TENANT-my.sharepoint.com/personal/USERPATH/_layouts/15/onedrive.aspx"

状态代码:

  • 200 = 用户存在,OneDrive 可访问
  • 401/403 = 用户存在,访问被拒绝
  • 404 = 用户不存在

用户 [email protected] 的示例:

curl -s -o /dev/null -w "%{http_code}" -I \
  "https://example-my.sharepoint.com/personal/john_doe_example_com/_layouts/15/onedrive.aspx"

6. 联合元数据(-FederationMeta)

检索包括签名证书和令牌端点在内的联合元数据。

# Replace DOMAIN with target domain
curl -s "https://login.microsoftonline.com/DOMAIN/FederationMetadata/2007-06/FederationMetadata.xml"

响应包含(XML):

  • 实体 ID
  • X509 签名证书
  • 令牌端点
  • NameID 格式
  • 声明类型
  • ADFS 服务器信息(如果已联合)

7. 无缝 SSO 检测(-SeamlessSSO)

检测桌面 SSO(无缝单一登录)是否已启用。

7.1 检查 SSO 配置

# Replace DOMAIN with target domain
curl -s "https://login.microsoftonline.com/getuserrealm.srf?login=user@DOMAIN&json=1"

查找: DesktopSsoEnabled: true

7.2 测试 Autologon 端点(如果已启用 SSO)

# Replace TENANT_ID with the tenant GUID
curl -s -o /dev/null -w "%{http_code}" \
  "https://autologon.microsoftazuread-sso.com/TENANT_ID/winauth/trust/2005/usernamemixed"

8. Azure 子域枚举(-SubdomainEnum)

发现与租户关联的 Azure 资源。使用 DNS 解析。

需要检查的核心 Azure 子域:

# Replace TENANT with tenant name

# Primary tenant domain
dig A TENANT.onmicrosoft.com

# SharePoint
dig A TENANT.sharepoint.com

# OneDrive
dig A TENANT-my.sharepoint.com

# Azure Blob Storage
dig A TENANT.blob.core.windows.net

# Azure Files
dig A TENANT.file.core.windows.net

# Azure Queue
dig A TENANT.queue.core.windows.net

# Azure Table
dig A TENANT.table.core.windows.net

# Key Vault
dig A TENANT.vault.azure.net

# Azure SQL
dig A TENANT.database.windows.net

# App Service
dig A TENANT.azurewebsites.net

# Kudu/Git Deployment
dig A TENANT.scm.azurewebsites.net

# Cloud Services
dig A TENANT.cloudapp.net
dig A TENANT.cloudapp.azure.com

# Exchange Online Protection
dig A TENANT.mail.protection.outlook.com

# Container Registry
dig A TENANT.azurecr.io

# Redis Cache
dig A TENANT.redis.cache.windows.net

# Service Bus
dig A TENANT.servicebus.windows.net

# Front Door
dig A TENANT.azurefd.net

# Azure AD B2C
dig A TENANT.b2clogin.com

# API Management
dig A TENANT.azure-api.net

# Traffic Manager
dig A TENANT.trafficmanager.net

# HDInsight
dig A TENANT.azurehdinsight.net

# Cosmos DB
dig A TENANT.documents.azure.com

# Cognitive Search
dig A TENANT.search.windows.net

# Cognitive Services
dig A TENANT.cognitiveservices.azure.com

组合排列示例:

# Common suffixes: dev, prod, staging, test, uat, qa, backup, dr, api, app, web, data
dig A TENANTdev.blob.core.windows.net
dig A TENANTprod.azurewebsites.net
dig A TENANTstaging.vault.azure.net

9. Autodiscover V2 枚举(-AutodiscoverEnum)

通过 Autodiscover V2 JSON 端点检查用户是否存在。

# Replace EMAIL with target email address
curl -s -o /dev/null -w "%{http_code}" -L --max-redirs 0 \
  "https://autodiscover-s.outlook.com/autodiscover/autodiscover.json?Email=EMAIL&Protocol=Autodiscoverv1"

状态代码:

  • 200 = 用户存在
  • 302(重定向)= 用户不存在
  • 401/403 = 用户存在(需要认证)

10. Autodiscover V1 枚举(-AutodiscoverV1Enum)

用于用户枚举的基于 XML 的旧版 Autodiscover 端点。

# Replace DOMAIN with target domain
# Replace EMAIL with target email address

curl -s -X POST "https://autodiscover.DOMAIN/autodiscover/autodiscover.xml" \
  -H "Content-Type: text/xml; charset=utf-8" \
  -d '<?xml version="1.0" encoding="utf-8"?>
<Autodiscover xmlns="http://schemas.microsoft.com/exchange/autodiscover/outlook/requestschema/2006">
  <Request>
    <EMailAddress>EMAIL</EMailAddress>
    <AcceptableResponseSchema>http://schemas.microsoft.com/exchange/autodiscover/outlook/responseschema/2006a</AcceptableResponseSchema>
  </Request>
</Autodiscover>'

响应指示符:

  • 响应中的 RedirectAddr = 用户存在
  • 响应中的 RedirectUrl = 可能表示用户存在
  • ErrorCode: InvalidUser = 用户不存在
  • ErrorCode: NoError = 用户存在

11. Exchange Web Services(EWS)探测(-EwsProbe)

探测 EWS 端点的暴露情况。

# Office 365 EWS endpoints
curl -s -o /dev/null -w "%{http_code}" \
  "https://outlook.office365.com/EWS/Exchange.asmx"

curl -s -o /dev/null -w "%{http_code}" \
  "https://outlook.office.com/EWS/Exchange.asmx"

# On-premises/custom domain endpoints
# Replace DOMAIN with target domain
curl -s -o /dev/null -w "%{http_code}" \
  "https://DOMAIN/EWS/Exchange.asmx"

curl -s -o /dev/null -w "%{http_code}" \
  "https://mail.DOMAIN/EWS/Exchange.asmx"

curl -s -o /dev/null -w "%{http_code}" \
  "https://ews.DOMAIN/EWS/Exchange.asmx"

表示可用性的状态代码:

  • 200、301、302、307、308 = 可用
  • 401、403 = 可用(需要认证)
  • 404 = 不可用

12. SharePoint/Teams 发现(-SharePointEnum)

发现 SharePoint 和 Teams 站点。

# Replace TENANT with tenant name

# Tenant root
curl -s -o /dev/null -w "%{http_code}" \
  "https://TENANT.sharepoint.com"

# OneDrive root
curl -s -o /dev/null -w "%{http_code}" \
  "https://TENANT-my.sharepoint.com"

# Common site names to check
# Sites: intranet, portal, hr, finance, it, projects, marketing, sales, support, admin, security, dev

curl -s -o /dev/null -w "%{http_code}" \
  "https://TENANT.sharepoint.com/sites/intranet"

curl -s -o /dev/null -w "%{http_code}" \
  "https://TENANT.sharepoint.com/sites/portal"
下载工具