{"repo":"nyxgeek/cloudkicker","free":true,"listed":false,"github":"https://github.com/nyxgeek/cloudkicker","clone":"git clone https://github.com/nyxgeek/cloudkicker.git","description":"self-hosted Azure OSINT tool","language":"PHP","stars":35,"topics":["azure","m365","o365","osint","pentesting","pentesting-tools"],"license":"GPL-3.0","category":"security-tools","readme_excerpt":"cloudkicker self-hosted Azure OSINT tool overview We have been using this tool internally for the last few years. Decided to release it so you can all laugh at my poor code design and bad php ;) It is very similar to what @DrAzureAD's OSINT tool does (https://aadinternals.com/osint/). While this version lacks a few of the extra features, it is self-contained, requires no account, and can be hosted anywhere. It also comes with your choice of an AI background complete with misspelled words, or a custom-made cloudkicking roundhouse machine background. Azure checks - [x] Tenants lookup - [x] Custom Domains lookup - [x] OneDrive hostname - [x] SharePoint hostname - [x] SharePoint/OneDrive Modern Auth enforcement - [x] Mail Record Existence (indicates AD Sync) - [x] ADFS Endpoint identification Installation - Setup This is made to run on a LAMP server. Make sure you have Apache installed and PHP enabled. Installation - Securing with htaccess CloudKicker won't let your perform lookups unless you have secured the endpoint with basic auth. The script will attempt to access itself on the public interface and see if it is prompted for auth. This is just a minor safeguard to stop somebody's machine from being abused. You are responsible for securing your own hosted apps. If you want to override this default behavior, simply update the script variable to , near the top of the script. 1. Create an htpasswd file Place this OUTSIDE of your web directory. This will prompt you to create a pass","default_branch":null,"files":null,"tree":[],"storefront":"/r/nyxgeek","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/nyxgeek/cloudkicker/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}