Dr. Nestori Syynimaa, aka DrAzureAD, is a Principal Identity Security Researcher at Microsoft Security Research. He maintains a notoriously interesting blog for Entra ID Administrators & identity security hawks called “AADInternals – The ultimate Entra ID (Azure AD) / Microsoft 365 hacking and admin toolkit”.
Besides an on-going blog about Entra ID security & management, DrAzureAD goes over tools & techniques for breach that all Entra ID Administrators should know, including:
- AAD Kill Chain – a collection of recon techniques and hacking tools DrAzureAD discovered and built over the last 10+ years
- AADInternals & AADInternals-Endpoints PowerShell modules – tools for administering and hacking Entra ID, Office 365, and Entra ID related endpoints.
- Links to publicly available Entra ID & Microsoft 365 PowerShell modules, tools
- OSINT Tenant Information Recon tool – tool will extract openly available information for the given tenant
- AADInternals Identity Federation Backdoor for GoldenSAML attacks – login to Microsoft 365 tenants using backdoors created with AADInternals
- Annual presentation recordings & PowerPoints at Defcon, Blackhat, BlueHat, Troopers, Disobey
I’m not going to pretend that I understand even half of what DrAzureAD addresses in his blog except to say that the Doctor comes very highly recommended by our security researchers in Microsoft’s cybersecurity incident response team (CIRT).
Visit AAD Internals at: