Entra ID

Cloud Security

Azure AD / Entra ID Token Theft and Abuse

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Azure and Entra ID Attacks: A Practical Primer with AADInternals and ROADtools

A hands-on introduction to Entra ID attacks: device code phishing, illicit consent grants, token theft, and the blue-team controls that stop them.
Cloud Security

Azure & Entra ID Attack Paths: Hunting Privilege Escalation with AzureHound

Advanced Entra ID attack paths: AzureHound enumeration, role assignment abuse, dynamic group injection, and OAuth consent grants.
Cloud Security

Abusing Azure Managed Identities: From IMDS Token Theft to ARM Takeover

How attackers steal IMDS access tokens from Azure Managed Identities and pivot into the ARM API, plus blue-team detection.