Azure / Entra
Azure and Entra offensive assessment
Identity is the new perimeter. We assess the tenant the way an attacker does, then hand your SOC detections they can actually write.
What we test
In scope
The Entra tenant, connected Azure subscriptions you name, hybrid trust to on-prem AD, and the identity paths that lead to tenant control. Duration is typically 8 to 12 days.
Out of scope
Physical, wireless, and broad phishing unless you add them. We do not run a scanner and call it an Entra assessment.
What you get
- Attack-path diagram
- Replay steps for every finding
- Detection gaps your SOC can write rules from
- Executive summary
- 90-minute readout
Tooling
ANIMO, used on the engagement
Azure Network Intel & Mission Ops
A tool we built and use on Azure and Entra assessments. One operator interface for tokens, tenant enumeration, and post-exploitation. It is not the engagement. We are.
- Capture, exchange, mint and analyse OAuth tokens, including access, refresh, PRT and SAS
- WhoAmI discovery with derived capability verdicts and fine-grained ARM action enumeration
- Reach Outlook, Calendar, Teams, OneDrive, SharePoint, Storage and Key Vault through Graph and ARM
- Remote execution over Azure VM runCommand, uploaded webshells and SSTI payloads
- Entra device registration for certificate-based persistence, TAP issuance and auth-method backdoors
- Password, SPN and refresh-token sprays, with engagement report generation
C++17 / Qt 6. Source on GitHub




Relevant research: PRT tokens, from initial access to long-term cloud control.
Contact
Written scope. Then the work.
Tell us what you want tested. A 20-minute call, then a written Statement of Work covering targets, rules of engagement, and out of scope.