Sunturai
Tool

github.com/Gerenios/AADInternals

https://github.com/Gerenios/AADInternals
Published on
github.com
Sources in this catalogue
2

ATT&CK techniques those detections carry

  • T1078Valid Accounts
  • T1078.004Cloud Accounts
  • T1528Steal Application Access Token
  • T1539Steal Web Session Cookie
  • T1550Use Alternate Authentication Material
  • T1550.001Application Access Token
  • T1069Permission Groups Discovery
  • T1069.003Cloud Groups
  • +3 more
Open the original

5 published detections cite this

Citing it, not covering it: each of these was written with this as evidence, and carries the source it came from and the licence it was published under.

Detections citing this reference
DetectionSeverity
Entra ID Device-Bound PRT from Unusual Device IPHigh
Entra ID Device-Bound PRT Replay via First-Party App from Unusual IPHigh
Entra ID OAuth Device Code Sign-in to Azure AD Graph EnumerationHigh
AADInternals PowerShell Cmdlets Execution - ProccessCreationHigh
AADInternals PowerShell Cmdlets Execution - PsScriptHigh

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice