Azure / Entra

Azure and Entra offensive assessment

Identity is the new perimeter. We assess the tenant the way an attacker does, then hand your SOC detections they can actually write.

What we test

  • Token theft and replay (PRT, refresh, SAS)
  • Illicit consent / device code
  • Conditional Access bypass paths
  • App and service principal abuse
  • Privileged role paths
  • Hybrid AD to Entra trust

In scope

The Entra tenant, connected Azure subscriptions you name, hybrid trust to on-prem AD, and the identity paths that lead to tenant control. Duration is typically 8 to 12 days.

Out of scope

Physical, wireless, and broad phishing unless you add them. We do not run a scanner and call it an Entra assessment.

What you get

  • Attack-path diagram
  • Replay steps for every finding
  • Detection gaps your SOC can write rules from
  • Executive summary
  • 90-minute readout

Tooling

ANIMO, used on the engagement

ANIMO

Azure Network Intel & Mission Ops

A tool we built and use on Azure and Entra assessments. One operator interface for tokens, tenant enumeration, and post-exploitation. It is not the engagement. We are.

  • Capture, exchange, mint and analyse OAuth tokens, including access, refresh, PRT and SAS
  • WhoAmI discovery with derived capability verdicts and fine-grained ARM action enumeration
  • Reach Outlook, Calendar, Teams, OneDrive, SharePoint, Storage and Key Vault through Graph and ARM
  • Remote execution over Azure VM runCommand, uploaded webshells and SSTI payloads
  • Entra device registration for certificate-based persistence, TAP issuance and auth-method backdoors
  • Password, SPN and refresh-token sprays, with engagement report generation

C++17 / Qt 6. Source on GitHub

ANIMO dashboard

Contact

Written scope. Then the work.

Tell us what you want tested. A 20-minute call, then a written Statement of Work covering targets, rules of engagement, and out of scope.