Entra ID 渗透侦察
原名:auditing-entra-id-with-aadinternals
驱动 AADInternals PowerShell 工具集,执行 Microsoft Entra ID 租户侦察、跨 Microsoft API 的访问令牌获取,以及联邦/AD FS 后门测试(Golden SAML、T1606.002),用于防御性验证。在授权的 Entra ID/Microsoft 365 红队评估中使用,以映射外部攻击面或验证 AD FS 签名证书能否抵御 Golden SAML。
- 分类
- 开发提效
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 1
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-21
- TRACE 评分
- 3.4 / 5
内容概览
Legal Notice: This skill is for authorized security testing, red-team engagements, and educational purposes only. AADInternals can forge SAML tokens and install federation backdoors that grant persistent impersonation of any tenant user. Use only against tenants you own or have explicit written authorization (rules of engagement) to test. Unauthorized use violates the Computer Fraud and Abuse Act and equivalent laws. AADInternals is the most comprehensive offensive/administrative PowerShell toolkit for Microsoft Entra ID (formerly Azure AD), Azure AD Connect, and Active Directory Federation Services (AD FS), authored by Dr. Nestori Syynimaa (Gerenios / Secureworks). It exposes hundreds of cmdlets (all prefixed AADInt) covering unauthenticated outsider reconnaissance, access-token acquisition for every Microsoft API, directory manipulation, AD FS/PTA attacks, and the technique it is most …