BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and configurable, traversable attack paths.
-
Updated
Mar 4, 2026 - Python
BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and configurable, traversable attack paths.
A collection of Microsoft cloud product logos
Bounces when a fish bites - Evilginx database monitoring with exfiltration automation
CA-PowerToys is a set of tools to help you manage Conditional Access policies. It is a command line tool that can be used to export, import, and clean up Conditional Access policies and associated Groups, helping to implement a Policy-as-Code approach.
Visualizes role assignments in an interactive network graph, helping security teams analyze access control structures.
Microsoft Cloud Purple tool
GraphAudit is a security auditing tool for Microsoft Entra ID that uses the Microsoft Graph API to detect risks and misconfigurations. It analyses Service Principal and Application–related objects, role assignments, and directory roles in-memory using customisable detection templates.
Add a description, image, and links to the entraid topic page so that developers can more easily learn about it.
To associate your repository with the entraid topic, visit your repo's landing page and select "manage topics."