{"repo":"blacklanternsecurity/offensive-azure","free":true,"listed":false,"github":"https://github.com/blacklanternsecurity/offensive-azure","clone":"git clone https://github.com/blacklanternsecurity/offensive-azure.git","description":"Collection of offensive tools targeting Microsoft Azure","language":"Python","stars":227,"topics":["azure","cloud","hacking","offensive-security","redteam-tools"],"license":"GPL-3.0","category":"deployment-docker-iac","readme_excerpt":"Collection of offensive tools targeting Microsoft Azure written in Python to be platform agnostic. The current list of tools can be found below with a brief description of their functionality. - ./Device Code/device code easy mode.py - Generates a code to be entered by the target user - Can be used for general token generation or during a phishing/social engineering campaign. - ./Access Tokens/token juggle.py - Takes in a refresh token in various ways and retrieves a new refresh token and an access token for the resource specified - ./Access Tokens/read token.py - Takes in an access token and parses the included claims information, checks for expiration, attempts to validate signature - ./Outsider Recon/outsider recon.py - Takes in a domain and enumerates as much information as possible about the tenant without requiring authentication - ./User Enum/user enum.py - Takes in a username or list of usernames and attempts to enumerate valid accounts using one of three methods - Can also be used to perform a password spray - ./Azure AD/get tenant.py - Takes in an access token or refresh token, outputs tenant ID and tenant Name - Creates text output file as well as BloodHound compatible aztenant file - ./Azure AD/get users.py - Takes in an access token or refresh token, outputs all users in Azure AD and all available user properties in Microsoft Graph - Creates three data files, a condensed json file, a raw json file, and a BloodHound compatible azusers file - ./Azure AD/get groups.","default_branch":null,"files":null,"tree":[],"storefront":"/r/blacklanternsecurity","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/blacklanternsecurity/offensive-azure/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}