Azure AD pentesting — tenant recon, service principal abuse, managed identity attacks.
Official PageAzure AD attack toolkit
Install-Module AADInternalsInvoke-AADIntReconAsOutsider; Get-AADIntLoginInformationOfficial Azure CLI
pip3 install azure-cliaz login; az account list; az role assignment list --allBloodHound for Azure
go install github.com/BloodHoundAD/AzureHound@latestazurehound list -t tenantid -u user -p pass -o output.jsonMicrosoft Graph API attack tool
git clone https://github.com/dafthack/GraphRunnerInvoke-GraphRunner; Get-GraphTokensAzure security assessment scripts
git clone https://github.com/NetSPI/MicroBurstInvoke-EnumerateAzureBlobs; Get-AzurePasswordsAzure AD exploration
pip3 install roadreconroadrecon gather -u user@tenant -p pass; roadrecon guiAzure token manipulation
git clone https://github.com/rvrsh3ll/TokenTacticsInvoke-RefreshToStorageToken; RoadUserToken