Hagrid29 / AbuseAzureAPIPermissionsView external linksLinks
Abuse Azure API permissions for red teaming
☆71Jan 24, 2023Updated 3 years ago
Alternatives and similar repositories for AbuseAzureAPIPermissions
Users that are interested in AbuseAzureAPIPermissions are comparing it to the libraries listed below
Sorting:
- Scripts to interact with Microsoft Graph APIs☆44Nov 7, 2024Updated last year
- A simple rpc2socks alternative in pure Go.☆31Jul 8, 2024Updated last year
- Microsoft Graph API post-exploitation toolkit☆95Jul 13, 2024Updated last year
- DFSCoerce exe revisited version with custom authentication☆42Jan 13, 2024Updated 2 years ago
- A tool for enumerating potential hosts that are open to GSSAPI abuse within Active Directory networks☆182Aug 16, 2025Updated 5 months ago
- To audit the security of read-only domain controllers☆118Nov 27, 2023Updated 2 years ago
- Abusing Azure services over C2☆368Jan 20, 2026Updated 3 weeks ago
- ☆156Dec 14, 2023Updated 2 years ago
- A python port of @dafthack's MFAsweep with some added OPSEC functionality. MFAde can be used to find single-factor authentication failure…☆50Jul 18, 2025Updated 6 months ago
- Abuse leaked token handles.☆134Dec 14, 2023Updated 2 years ago
- Tooling related to the WAM Bam - Recovering Web Tokens From Office blog post☆130Jan 14, 2023Updated 3 years ago
- ☆102Sep 5, 2024Updated last year
- Lateral Movement via the .NET Profiler☆100Nov 21, 2024Updated last year
- A fork of the great TokenTactics with support for CAE and token endpoint v2☆385Updated this week
- C# implementation of Get-AADIntSyncCredentials from AADInternals, which extracts Azure AD Connect credentials to AD and Azure AD from AAD…☆45Jun 24, 2023Updated 2 years ago
- Cobalt Strike + Brute Ratel C4 Beacon Object File (BOF) Conversion of the Mockingjay Process Injection Technique☆158Nov 7, 2023Updated 2 years ago
- Research into Undocumented Behavior of Azure AD Refresh Tokens☆337Feb 23, 2024Updated last year
- Disconnected RSAT - A method of running Group Policy Manager, Certificate Authority and Certificate Templates MMC snap-ins from non-domai…☆273Dec 27, 2024Updated last year
- ☆18May 14, 2025Updated 8 months ago
- ☆43Jul 9, 2024Updated last year
- A tool leveraging Kerberos tickets to get Microsoft 365 access tokens using Seamless SSO☆232Aug 25, 2024Updated last year
- A Cobalt Strike payload generator and lateral movement aggressor script which places Beacon shellcode into a custom shellcode loader☆45Sep 25, 2024Updated last year
- An In-memory Embedding of CPython☆31May 24, 2021Updated 4 years ago
- just manipulatin these here tokens yes sir nothing weird☆22Apr 18, 2022Updated 3 years ago
- SCEP request tool for AD CS and Intune☆73Oct 24, 2025Updated 3 months ago
- ☆64May 31, 2024Updated last year
- ☆290Jul 20, 2023Updated 2 years ago
- TokenSmith generates Entra ID access & refresh tokens on offensive engagements. It is suitable for both covert adversary simulations and …☆376Jan 23, 2025Updated last year
- ☆105Oct 27, 2022Updated 3 years ago
- A tool for pointesters to find candies in SharePoint☆277Nov 4, 2022Updated 3 years ago
- Ask a TGS on behalf of another user without password☆481Mar 30, 2025Updated 10 months ago
- Source code and examples for PassiveAggression☆64Jun 6, 2024Updated last year
- A web assembly (WASM) phishing lure generator based on pre-built templates and written in Rust with some GenAI assistance. W.A.L.K. aims …☆99Sep 5, 2024Updated last year
- Example code samples from our ScriptBlock Smuggling Blog post☆94Jun 18, 2024Updated last year
- ☆190Nov 21, 2024Updated last year
- BOF for C2 framework☆44Nov 9, 2024Updated last year
- A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.☆301Oct 26, 2022Updated 3 years ago
- ☆50Jun 4, 2025Updated 8 months ago
- DavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced (the …☆565Jun 5, 2023Updated 2 years ago