detecting-entra-offensive-tools-in-graph-logs

mukul975/detecting-entra-offensive-tools-in-graph-logs · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Hunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics for fingerprints of offensive Entra ID tools such as ROADtools, AADInternals, and AzureHound.

SKILL.md

Files

This skill is a package of 5 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.5 KB
  • 📄standards.md 1.3 KB
  • 📁scripts
  • ⚙️agent.py 5.2 KB
  • 📄LICENSE 11.0 KB

Related

  1. detecting-azure-service-principal-abuse · mukul975 bundle
    Detect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments.
    24.6k
    repo stars
  2. detecting-golden-ticket-attacks-in-kerberos-logs · mukul975 bundle
    Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs.
    24.6k
    repo stars
  3. hunting-saas-sso-token-abuse · mukul975 bundle
    Detect SSO and OAuth token replay and SaaS lateral movement using identity telemetry from Microsoft Entra ID and Okta.
    24.6k
    repo stars
  4. detecting-oauth-token-theft · mukul975 bundle
    Detects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID token protection, conditional access policies, and sign-in anomaly detection.
    24.6k
    repo stars
  5. detecting-azure-lateral-movement · mukul975 bundle
    Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, token theft, and cross-tenant pivoting.
    24.6k
    repo stars
  6. building-cloud-siem-with-sentinel · mukul975 bundle
    Deploy Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security operations across AWS, Azure, and GCP.
    24.6k
    repo stars

Frequently asked questions

How do I install the detecting-entra-offensive-tools-in-graph-logs skill?

Run npx skillmds add mukul975/detecting-entra-offensive-tools-in-graph-logs in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the detecting-entra-offensive-tools-in-graph-logs skill do?

Hunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics for fingerprints of offensive Entra ID tools such as ROADtools, AADInternals, and AzureHound. It is listed under Security, Data & Analytics, Data Analysis, Incident Response on SkillMD.

Is detecting-entra-offensive-tools-in-graph-logs safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with detecting-entra-offensive-tools-in-graph-logs?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is detecting-entra-offensive-tools-in-graph-logs free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published detecting-entra-offensive-tools-in-graph-logs?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.