A collection of Azure AD/Entra tools for offensive and defensive security purposes
Manages, configures, extracts and monitors Microsoft 365 tenant configurations
Monkey365 provides a tool for security consultants to easily conduct not only Microsoft 365, but also Azure subscriptions and Microsoft Entra ID security configuration reviews.
The missing reverse proxy for ssh scp
retrieve information via O365 and AzureAD with a valid cred
PowerShell module to export a local copy of an Entra (Azure AD) tenant configuration.
Easy and secure implementation of Azure Entra ID (previously AD) for your FastAPI APIs 🔒 B2C, single- and multi-tenant support.
365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack.
Terraform provider for Azure Active Directory
The Azure Active Directory Incident Response PowerShell module provides a number of tools, developed by the Azure Active Directory Product Group in conjunction with the Microsoft Detection and Respons...
Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive web-based user interface built with the Python Flask...
MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).
AD Health Check, Send HTML Email, Ping machines, Encrypt Password,Bulk Password,Microsoft Teams,Monitor Certificate expiry, Monitor cert expiry, AD attributes, IP to Hostname, Export AD group, CSV to...
A React wrapper for Azure AD using the Microsoft Authentication Library (MSAL). The easiest way to integrate AzureAD with your React for authentication.
Halberd : Multi-Cloud Attack Tool
A lightweight PowerShell tool for assessing the security posture of Microsoft Entra ID environments. It helps identify privileged objects, risky assignments, and potential misconfigurations.
The Contoso Traders app is a sample application showcasing Playwright, Azure Load Testing, Azure Chaos Studio.
Community project to classify, identify and protect your privileges based on Enterprise Access Model (EAM)
Provider agnostic OAuth2 Authorization Code flow with PKCE for React