📒
My Pentesting Cheatsheet
search
Ctrlk
  • Home
  • Commands Only Summarychevron-right
  • Preparationchevron-right
  • Information Gathering
  • Vulnerability Assessment
  • Pentesting Machine
  • Enumerationchevron-right
  • Footprintingchevron-right
  • Web Information Gatheringchevron-right
  • Vulnerability Assessment
  • File Transferschevron-right
  • Shells & Payloadschevron-right
  • Password Attackschevron-right
  • Attacking Common Serviceschevron-right
  • Pivoting, Tunneling, and Port Forwardingchevron-right
  • Active Directory Enumeration & Attackschevron-right
  • Using Web Proxies
  • Login Brute Forcing
  • SQL Injection Fundamentalschevron-right
  • SQLMap Essentialschevron-right
  • Cross-Site Scripting (XSS)chevron-right
  • File Inclusion
  • File Upload Attackschevron-right
  • Command Injectionschevron-right
  • Web Attackschevron-right
  • Attacking Common Applicationschevron-right
  • Privilege Escalationchevron-right
  • Documentation & Reportingchevron-right
  • Attacking Enterprise Networkschevron-right
  • Deobfuscation
  • Metasploitchevron-right
  • Custom compiled files
  • XSS
  • Azure AD (Entra ID)
gitbookPowered by GitBook
block-quoteOn this pagechevron-down

Azure AD (Entra ID)

hashtag
Azure AD: Reconnaissance

hashtag
Get Tenant Name

https://login.microsoftonline.com/getuserrealm.srf/[email protected]&xml=1

hashtag
Get Tenant ID

LogoGitHub - Gerenios/AADInternals: AADInternals PowerShell module for administering Azure AD and Office 365GitHubchevron-right

hashtag
Get Tenant Domains

hashtag
Enumerate emails

LogoGitHub - y0k4i-1337/o365creeper-ng: Python script that performs email address validation against Office 365 without submitting login attempts.GitHubchevron-right

hashtag
Azure services

LogoGitHub - NetSPI/MicroBurst: A collection of scripts for assessing Microsoft Azure securityGitHubchevron-right

hashtag
Enumerate Subdomains

(Misc folder)

hashtag
Public Azure Blobs

(Misc Folder)

PreviousXSSchevron-left

Last updated 8 months ago

  • Azure AD: Reconnaissance
  • Get Tenant Name
  • Get Tenant ID
  • Get Tenant Domains
  • Enumerate emails
  • Azure services
Install-Module AADInternals
Get-AADIntTenantID -Domain domain.it
Get-AADIntTenantDomains -Domain domain.it
Import-Module .\MicroBurst.psm1
Invoke-EnumerateAzureSubDomains.ps1 -Base domain.com -Verbose
Invoke-EnumerateAzureBlobs.ps1 -Base domain.com -Verbose