{"adoption": {"forks": 367, "observed_at": "2026-08-28T04:07:00.624660+00:00", "stars": 2554}, "canonical_url": "https://ross.abutalabs.com/products/azuread-attack-defense", "card": {"archived": false, "artifact_type": "learning-resource", "description": "This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected.", "domain": ["security", "cloud-computing", "documentation"], "enriched": true, "function": ["security", "monitoring", "documentation"], "health_score": 74, "homepage": null, "language": "PowerShell", "license": null, "license_family": "other", "maturity": "active", "member_repos": ["Cloud-Architekt/AzureAD-Attack-Defense"], "name": "Cloud-Architekt/AzureAD-Attack-Defense", "platform": ["cloud"], "pushed_at": "2026-06-30T12:29:45+00:00", "repo": "Cloud-Architekt/AzureAD-Attack-Defense", "stars": 2554, "tags": ["entra-id", "azure-active-directory", "mitre-attack", "identity-security", "playbook", "detection", "mitigation", "microsoft-sentinel", "itdr", "web-server"], "topics": ["azureactivedirectory", "itdr", "microsoftentraid", "microsoftsentinel"], "urls": [], "use_cases": ["learn how password spray attacks on Entra ID are detected and mitigated", "understand adversary-in-the-middle phishing attacks against Azure AD", "detect token replay and PRT theft in Microsoft 365", "secure service principals used in Azure DevOps pipelines", "harden Entra ID consent grant permissions", "map identity attacks to MITRE ATT&CK techniques", "build identity threat detection rules in Microsoft Sentinel", "prevent lateral movement from compromised Active Directory to Entra ID"], "what_it_is": "A community-maintained playbook documenting common attack scenarios against Microsoft Entra ID (Azure AD) with corresponding detection and mitigation guidance. Each chapter maps attack techniques to MITRE ATT&CK and shows how to detect them using the Microsoft security stack.", "when_to_avoid": ["you need a runnable security tool rather than documentation (though it references tools like EIDSCA)", "you secure non-Microsoft identity providers like Okta or Keycloak", "you need general on-premises Active Directory hardening unrelated to Entra ID"], "when_to_choose": ["you administer or secure a Microsoft Entra ID / Azure AD tenant", "you are building detection rules for identity attacks in Sentinel or Defender", "you want MITRE ATT&CK-mapped guidance for cloud identity threats", "you are preparing for red team or attack simulations against Azure AD"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/azuread-attack-defense", "repo": "Cloud-Architekt/AzureAD-Attack-Defense", "role": "main", "score": 73}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.624660+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T02:23:44.418383+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f9bb863123dd257c0cecb9a759cbd692f929ecd62fc1e08f642ebe41029d596d", "fetched_at": "2026-08-28T04:07:00.624660+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Cloud-Architekt/AzureAD-Attack-Defense"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.624660+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T02:23:44.418383+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f9bb863123dd257c0cecb9a759cbd692f929ecd62fc1e08f642ebe41029d596d", "fetched_at": "2026-08-28T04:07:00.624660+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Cloud-Architekt/AzureAD-Attack-Defense"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T02:23:44.418383+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f9bb863123dd257c0cecb9a759cbd692f929ecd62fc1e08f642ebe41029d596d", "fetched_at": "2026-08-28T04:07:00.624660+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Cloud-Architekt/AzureAD-Attack-Defense"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.624660+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.624660+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.624660+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T02:23:44.418383+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f9bb863123dd257c0cecb9a759cbd692f929ecd62fc1e08f642ebe41029d596d", "fetched_at": "2026-08-28T04:07:00.624660+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Cloud-Architekt/AzureAD-Attack-Defense"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.624660+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.624660+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T02:23:44.418383+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f9bb863123dd257c0cecb9a759cbd692f929ecd62fc1e08f642ebe41029d596d", "fetched_at": "2026-08-28T04:07:00.624660+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Cloud-Architekt/AzureAD-Attack-Defense"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.624660+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.624660+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.624660+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T02:23:44.418383+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f9bb863123dd257c0cecb9a759cbd692f929ecd62fc1e08f642ebe41029d596d", "fetched_at": "2026-08-28T04:07:00.624660+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Cloud-Architekt/AzureAD-Attack-Defense"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.624660+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.624660+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T02:23:44.418383+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f9bb863123dd257c0cecb9a759cbd692f929ecd62fc1e08f642ebe41029d596d", "fetched_at": "2026-08-28T04:07:00.624660+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Cloud-Architekt/AzureAD-Attack-Defense"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T02:23:44.418383+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f9bb863123dd257c0cecb9a759cbd692f929ecd62fc1e08f642ebe41029d596d", "fetched_at": "2026-08-28T04:07:00.624660+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Cloud-Architekt/AzureAD-Attack-Defense"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T02:23:44.418383+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f9bb863123dd257c0cecb9a759cbd692f929ecd62fc1e08f642ebe41029d596d", "fetched_at": "2026-08-28T04:07:00.624660+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Cloud-Architekt/AzureAD-Attack-Defense"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T02:23:44.418383+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f9bb863123dd257c0cecb9a759cbd692f929ecd62fc1e08f642ebe41029d596d", "fetched_at": "2026-08-28T04:07:00.624660+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Cloud-Architekt/AzureAD-Attack-Defense"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 90, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": ["no_releases", "no_license"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2134, "days_push": 64, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 73, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}