National Cyber Warfare Foundation (NCWF)

Mapping offensive Entra ID tooling fingerprints with EntraTrace


0 user ratings
2026-09-23 09:29:06
milo
Red Team (CNA)
"Mapping

EntraTrace is a defensive knowledge base that documents the API endpoints and UserAgent strings left behind by offensive tools targeting Microsoft Entra ID, enabling detection engineering and incident response.








ToolBert-JanP/EntraTrace — defensive research knowledge base profiling offensive tooling behavior against Microsoft Entra ID
CategoryDetection engineering / threat research (Python)
Primary UseBuilding detections, Microsoft Sentinel / SIEM hunting queries, and identifying offensive identity tools from Microsoft Graph and Azure AD Graph telemetry
Safe UseDesigned for defenders on authorized engagements: blue teams, IR analysts, and detection engineers operating within their own or their client's sanctioned environments
Telemetry NoteThe tool itself produces no attack traffic; it catalogs UserAgent strings and API call patterns that defenders can match against Entra ID sign-in and Graph activity logs

EntraTrace occupies an unusual and welcome niche in the security tooling landscape: it is a purely defensive project built around the study of offensive tools. Rather than helping you attack Microsoft Entra ID, it systematically documents what well-known offensive tooling looks like from the defender's side of the fence — which API endpoints get touched, how often, and with which HTTP UserAgent strings. The author, Bert-JanP, frames it as an effort to bridge offensive identity-tooling research and defensive security operations, and the repository structure reflects that ambition.


The core artifact of the project is a set of tool profiles stored as YAML files under Profiles/. At the time of writing, the README's generated profile table covers nineteen tools, including AzureHound, AADInternals, ROADtools, GraphRunner, MSOLSpray, TeamFiltration, TokenTactics, TokenTacticsV2, PingCastle, MicroBurst, PowerZure, MFASweep, GraphSpy, o365spray, o365enum, Stormspotter, TokenSmith, ropci, and graphpython. That is a fairly comprehensive inventory of the current Entra ID attack surface, spanning reconnaissance, token manipulation, password spraying, and Graph-based collection tooling.


Each profile quantifies observable behavior along three axes: unique APIs touched, unique API calls recorded, and distinct user agents observed. The numbers vary dramatically and tell their own story about detection potential. ROADtools leads with 434 unique API calls across 4 APIs, a reflection of how comprehensively it walks the directory. graphpython records 119 calls and 17 user agents, AADInternals 110 calls and 18 user agents, and GraphRunner 67 calls with 21 user agents. At the opposite extreme, MSOLSpray shows a single API and a single call — exactly what you would expect from a focused password-spraying utility, and correspondingly harder to distinguish from benign auth traffic.


The user-agent dimension is where EntraTrace is arguably most immediately actionable. Eight of the profiled tools carry distinctive user agents: TokenTacticsV2 exposes 23, TokenTactics 16, MFASweep 11, graphpython 17, AADInternals 18. Several others — AzureHound, MicroBurst, MSOLSpray, PowerZure — show zero, meaning they either present no custom agent or inherit whatever the underlying runtime sends. That asymmetry matters operationally: a defanged static string list is a cheap, high-fidelity detection primitive for the first group, while the second group demands behavioral detection built on API call patterns instead.


Internally, the project is a Python pipeline with two main entry points under Scripts/. ExtractToolBehavior.py is the heavy lifter: it clones the repositories of offensive tools locally, instruments or analyzes their code, and extracts API behavior into profile YAML files. It reads target repository URLs from Profiles/Tools.txt when present, otherwise falling back to every repository_url embedded in the existing profile YAMLs. SummarizeUserAgents.py then flattens the user-agent data from all profiles into a CSV under Indicator Lists/, purpose-built for hunting imports.


The repository is refreshed daily, which is a sensible cadence given how quickly offensive identity tooling evolves, but local deployment is explicitly supported. The basic invocations are straightforward: python .\Scripts\ExtractToolBehavior.py --all-profiles --output-dir .\Profiles refreshes every profile, and python .\Scripts\SummarizeUserAgents.py --profiles-dir .\Profiles --output .\Indicator Lists\UserAgents.csv regenerates the hunting CSV. Both scripts expose -h/--help for the full parameter surface, and the README sensibly advises confirming options there before running.


One caveat deserves emphasis and the README flags it honestly with a warning marker: running ExtractToolBehavior.py locally downloads repositories containing offensive tooling onto your workstation. That is entirely legitimate research activity, but it will trip endpoint security controls, and in a corporate environment you should coordinate with your SOC or run it in a sanctioned lab VM. This is a defensible-intel generation pipeline, not something to fire off casually on a production analyst box.


The stated use cases are squarely defensive: building detections for known offensive tools, developing Microsoft Sentinel and SIEM hunting queries, investigating suspicious Entra ID and Microsoft Graph activity, identifying tooling during incident response, researching identity-tool behavior, and improving overall visibility into identity attack techniques. The curated related-content section reinforces this, linking to primary material on MicrosoftGraphActivityLogs, the newer GraphApiAuditEvents log source, and Invictus IR's write-up on the arrival of AADGraphActivityLogs — effectively a reading list for the telemetry that EntraTrace profiles are designed to be matched against.


Two aspects of the project's provenance are worth noting. First, it is BSD-3-Clause licensed with a small but real community of 65 stars, reasonable for a niche detection-engineering resource. Second, the README is transparent that development is AI-assisted, with human review and validation of the output. For a project whose entire value proposition is data accuracy — a wrong API path or user-agent string produces a broken detection — that human-validation claim is the part practitioners should verify by sampling profiles against real telemetry before trusting them wholesale.


The project is explicitly marked as early development, with data, coverage, and functionality expected to evolve, and contributions of research and additional tool analysis are welcomed. That status should temper expectations: the profile set is already broad but the depth per tool varies, and the extraction pipeline's methodology for deriving call counts is not fully documented in the README. Treat the current dataset as a strong starting corpus rather than an authoritative census of offensive Entra ID behavior.


For blue teams maturing their identity defense program, EntraTrace fills a real gap. Detection content for Entra ID tends to lag offensive tooling by months, and this project shortens that loop by converting attack-tool source code into structured, queryable behavioral indicators. Pair the user-agent CSV with MicrosoftGraphActivityLogs and GraphApiAuditEvents hunting, use the API call profiles to shape frequency and sequence analytics, and validate everything in your own tenant before production deployment — the workflow the README clearly intends.



Official project repository for Bert-JanP/EntraTrace.

Download Tool

Educational analysis for authorized security professionals. Use only in controlled, authorized environments.






Source: OffensiveSec
Source Link: https://www.offsecblog.com/2026/09/mapping-offensive-entra-id-tooling.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.