Ross ROSS = Recommend OSS · open-source software intelligence for agents

Cloud-Architekt/AzureAD-Attack-Defense resource

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected. observed · 2026-08-28

github.com/Cloud-Architekt/AzureAD-Attack-Defense · PowerShell observed · 2026-08-28

Health v2 · maintenance only

73/100

  • Activity 90
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2134
  • days_rel: n/a
  • days_push: 64
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2554 stars · 367 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A community-maintained playbook documenting common attack scenarios against Microsoft Entra ID (Azure AD) with corresponding detection and mitigation guidance. Each chapter maps attack techniques to MITRE ATT&CK and shows how to detect them using the Microsoft security stack.

Use cases

  • learn how password spray attacks on Entra ID are detected and mitigated
  • understand adversary-in-the-middle phishing attacks against Azure AD
  • detect token replay and PRT theft in Microsoft 365
  • secure service principals used in Azure DevOps pipelines
  • harden Entra ID consent grant permissions
  • map identity attacks to MITRE ATT&CK techniques
  • build identity threat detection rules in Microsoft Sentinel
  • prevent lateral movement from compromised Active Directory to Entra ID

When to choose

  • you administer or secure a Microsoft Entra ID / Azure AD tenant
  • you are building detection rules for identity attacks in Sentinel or Defender
  • you want MITRE ATT&CK-mapped guidance for cloud identity threats
  • you are preparing for red team or attack simulations against Azure AD

When to avoid

  • you need a runnable security tool rather than documentation (though it references tools like EIDSCA)
  • you secure non-Microsoft identity providers like Okta or Keycloak
  • you need general on-premises Active Directory hardening unrelated to Entra ID

Facets

learning-resource · maturity active

security monitoring documentation security cloud-computing documentation cloud entra-id azure-active-directory mitre-attack identity-security playbook detection mitigation microsoft-sentinel itdr web-server

1 source

Member repositories

RepositoryRoleHealth v2
Cloud-Architekt/AzureAD-Attack-Defensemain73

For agents

markdown · JSON · MCP: product_card(name="Cloud-Architekt/AzureAD-Attack-Defense")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem