Ross ROSS = Recommend OSS · open-source software intelligence for agents

cisagov/Sparrow

Sparrow.ps1 was created by CISA's Cloud Forensics team to help detect possible compromised accounts and applications in the Azure/m365 environment. observed · 2026-08-28

github.com/cisagov/Sparrow · PowerShell · CC0-1.0 (permissive) · archived observed · 2026-08-28

Health v2 · maintenance only

10/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100

Flags: archived

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2078
  • days_rel: n/a
  • days_push: 1345
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1430 stars · 184 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Sparrow.ps1 is a PowerShell script from CISA's Cloud Forensics team that helps incident responders detect possibly compromised accounts and applications in Azure/Microsoft 365 environments. It checks the unified audit log for indicators of compromise, lists Azure AD domains, and inspects service principals and Graph API permissions, exporting results to CSV files.

Use cases

  • detect compromised accounts in azure m365
  • hunt for solarwinds-style identity attacks in my tenant
  • audit azure ad service principals and graph api permissions
  • check unified audit log for indicators of compromise
  • investigate suspicious application activity in office 365
  • export m365 audit findings to csv for analysis

When to choose

  • you are an incident responder investigating identity or authentication-based attacks in an Azure/M365 tenant
  • you need a read-only sweep of unified audit logs, Azure AD domains, and service principals
  • you want CSV outputs you can feed into a dashboard like Aviary or analyze manually

When to avoid

  • you need actively maintained tooling - the repo was archived in December 2022 and is no longer maintained
  • you require comprehensive cloud security monitoring beyond the narrow scope of federated identity and application attacks
  • your tenant lacks the required E5/G5 license or unified audit logging, which some checks depend on

Facets

cli-tool · maturity abandoned

security monitoring developer-tools security cloud-computing developer-tools windows cli cloud azure m365 incident-response forensics powershell threat-hunting solarwinds azure-ad unified-audit-log csv-export cisa archived

1 source

Member repositories

RepositoryRoleHealth v2
cisagov/Sparrowmain10

For agents

markdown · JSON · MCP: product_card(name="cisagov/Sparrow")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem