Azure AppHunter is an open-source tool created for security researchers, red teamers and defenders to help them identify excessive privileges assigned to Service Principals
☆105May 31, 2026Updated 2 months ago
Alternatives and similar repositories for Azure-AppHunter
Users that are interested in Azure-AppHunter are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆148Sep 9, 2025Updated 11 months ago
- Create Entra Global Admin accounts from On-Prem☆25Jul 28, 2025Updated last year
- Performs review of Entra ID users and their assigned roles based on least privilege principle and actual Entra ID operations performed wi…☆33Feb 23, 2026Updated 5 months ago
- Eve is a JAMF exploitation toolkit used to interact with locally hosted JAMF servers and those hosted on jamfcloud.com.☆50May 1, 2026Updated 3 months ago
- SCEP request tool for AD CS and Intune☆77Oct 24, 2025Updated 9 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- tool for enumeration & bulk download of sensitive files found in SharePoint environments☆89Apr 2, 2025Updated last year
- Enhance Your Active Directory Password Spraying with User Intelligence.☆337Dec 29, 2025Updated 7 months ago
- Group Policy Objects manipulation and exploitation framework☆317Dec 7, 2025Updated 8 months ago
- An HTA Application which builds Azure (Entra) Scenarios for Red Team Simulations☆63Aug 18, 2025Updated 11 months ago
- ☆99Apr 14, 2026Updated 4 months ago
- Verified Entity Identity Lock (Expose hidden trust paths in your AWS IAM setup before they become security risks.)☆16Apr 20, 2026Updated 3 months ago
- .NET Post-Exploitation Utility for Abusing Strong Explicit Certificate Mappings in ADCS☆154Feb 10, 2025Updated last year
- Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID☆181Jul 10, 2026Updated last month
- 🖥️ Windows 🚀 A Windows tool for emergency privacy: instantly deletes sensitive data and active logins to protect my information during …☆56Jul 5, 2026Updated last month
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.☆276Sep 23, 2025Updated 10 months ago
- Windows anti-debugging sandbox☆42Jul 8, 2026Updated last month
- ☆49Apr 9, 2025Updated last year
- A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.☆974May 6, 2026Updated 3 months ago
- BlackCat is a PowerShell module designed to validate the security of Microsoft Azure. It provides a set of functions to identify potentia…☆206Aug 5, 2026Updated last week
- A security tool that detects malicious packages from external vulnerability feeds and searches for them in your package registries or art…☆70Nov 27, 2025Updated 8 months ago
- Scripts to enumerate and report on Entra Conditional Access☆42Sep 5, 2025Updated 11 months ago
- PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via …☆167Jan 25, 2026Updated 6 months ago
- Script to check Azure Front Door WAF for insecure RemoteAddr variable☆30Jul 11, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- a small script to collect information from a management point☆37Jan 19, 2026Updated 6 months ago
- A tool to enumerate and download files from the System Center Configuration Manager (SCCM) SMB share (SCCMContentLib)☆22Jul 27, 2024Updated 2 years ago
- Random BOFs for LDAP tradecraft☆73Sep 9, 2025Updated 11 months ago
- Enumerate active EDR's on the system☆153Sep 23, 2025Updated 10 months ago
- Putting a leash on naughty AWS permissions☆137Sep 5, 2025Updated 11 months ago
- A lightweight PowerShell tool for assessing the security posture of Microsoft Entra ID environments. It helps identify privileged object…☆458Jun 16, 2026Updated last month
- Secrets scanner with a twist... this is for getting threat actor credentials from MALWARE. Acquire TA creds from FLOSS exports, memdumps…☆39Updated this week
- Outfits your ludus AD domain with BadBlood info.☆17Aug 5, 2025Updated last year
- A fork of the great TokenTactics with support for CAE and token endpoint v2☆444Updated this week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A Python script for creating `.lnk` (shortcut) files with embedded encoded data and packaging them into ZIP archives.☆92Jan 8, 2025Updated last year
- This is practice VM for malware development☆180Nov 17, 2025Updated 8 months ago
- Abusing Azure services over C2☆380Jan 20, 2026Updated 6 months ago
- Creating attacks paths across management and data planes☆64Jul 28, 2026Updated 2 weeks ago
- Inboxfuscation is an advanced offensive & defensive framework for mailbox rule obfuscation and detection in Exchange environments.☆84Sep 11, 2025Updated 11 months ago
- Organizational asset discovery tool with 20+ plugins covering certificate transparency, passive DNS, and all 5 Regional Internet Registri…☆86Updated this week
- AWS services enumerator for penetration testing☆21Nov 11, 2025Updated 9 months ago