πŸ“’
My Pentesting Cheatsheet
search
⌘Ctrlk
πŸ“’
My Pentesting Cheatsheet
  • Home
  • Commands Only Summary
  • Preparation
  • Information Gathering
  • Vulnerability Assessment
  • Pentesting Machine
  • Enumeration
  • Footprinting
  • Web Information Gathering
  • Vulnerability Assessment
  • File Transfers
  • Shells & Payloads
  • Password Attacks
  • Attacking Common Services
  • Pivoting, Tunneling, and Port Forwarding
  • Active Directory Enumeration & Attacks
  • Using Web Proxies
  • Login Brute Forcing
  • SQL Injection Fundamentals
  • SQLMap Essentials
  • Cross-Site Scripting (XSS)
  • File Inclusion
  • File Upload Attacks
  • Command Injections
  • Web Attacks
  • Attacking Common Applications
  • Privilege Escalation
  • Documentation & Reporting
  • Attacking Enterprise Networks
  • Deobfuscation
  • Metasploit
  • Custom compiled files
  • XSS
  • Azure AD (Entra ID)
gitbookPowered by GitBook
block-quoteOn this pagechevron-down

Azure AD (Entra ID)

hashtag
Azure AD: Reconnaissance

hashtag
Get Tenant Name

https://login.microsoftonline.com/getuserrealm.srf/[email protected]&xml=1

hashtag
Get Tenant ID

LogoGitHub - Gerenios/AADInternals: AADInternals PowerShell module for administering Azure AD and Office 365GitHubchevron-right

hashtag
Get Tenant Domains

hashtag
Enumerate emails

LogoGitHub - y0k4i-1337/o365creeper-ng: Python script that performs email address validation against Office 365 without submitting login attempts.GitHubchevron-right

hashtag
Azure services

LogoGitHub - NetSPI/MicroBurst: A collection of scripts for assessing Microsoft Azure securityGitHubchevron-right

hashtag
Enumerate Subdomains

(Misc folder)

hashtag
Public Azure Blobs

(Misc Folder)

PreviousXSSchevron-left

Last updated 9 months ago

  • Azure AD: Reconnaissance
  • Get Tenant Name
  • Get Tenant ID
  • Get Tenant Domains
  • Enumerate emails
  • Azure services
Install-Module AADInternals
Get-AADIntTenantID -Domain domain.it
Get-AADIntTenantDomains -Domain domain.it
Import-Module .\MicroBurst.psm1
Invoke-EnumerateAzureSubDomains.ps1 -Base domain.com -Verbose
Invoke-EnumerateAzureBlobs.ps1 -Base domain.com -Verbose