cisagov/Sparrow
Sparrow.ps1 was created by CISA's Cloud Forensics team to help detect possible compromised accounts and applications in the Azure/m365 environment. observed · 2026-08-28
Health v2 · maintenance only
10/100
- Activity 0
- Release rhythm 8
- Longevity 100
Flags: archived
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2078
- days_rel: n/a
- days_push: 1345
- n_releases_24m: 0
Adoption not part of the score
1430 stars · 184 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Sparrow.ps1 is a PowerShell script from CISA's Cloud Forensics team that helps incident responders detect possibly compromised accounts and applications in Azure/Microsoft 365 environments. It checks the unified audit log for indicators of compromise, lists Azure AD domains, and inspects service principals and Graph API permissions, exporting results to CSV files.
Use cases
- detect compromised accounts in azure m365
- hunt for solarwinds-style identity attacks in my tenant
- audit azure ad service principals and graph api permissions
- check unified audit log for indicators of compromise
- investigate suspicious application activity in office 365
- export m365 audit findings to csv for analysis
When to choose
- you are an incident responder investigating identity or authentication-based attacks in an Azure/M365 tenant
- you need a read-only sweep of unified audit logs, Azure AD domains, and service principals
- you want CSV outputs you can feed into a dashboard like Aviary or analyze manually
When to avoid
- you need actively maintained tooling - the repo was archived in December 2022 and is no longer maintained
- you require comprehensive cloud security monitoring beyond the narrow scope of federated identity and application attacks
- your tenant lacks the required E5/G5 license or unified audit logging, which some checks depend on
Facets
cli-tool · maturity abandoned
security monitoring developer-tools security cloud-computing developer-tools windows cli cloud azure m365 incident-response forensics powershell threat-hunting solarwinds azure-ad unified-audit-log csv-export cisa archived
1 source
- readme: https://github.com/cisagov/Sparrow · fetched 2026-08-28 · b1bf6b0ce1c8
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| cisagov/Sparrow | main | 10 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem