MSFTRecon: Unauthenticated Recon Tool for Microsoft 365 & Azure

MSFTRecon is a reconnaissance tool designed for red teamers and security professionals to map Microsoft 365 and Azure tenant infrastructure. It performs comprehensive enumeration without requiring authentication, helping identify potential security misconfigurations and attack vectors.

MSFTRecon provides valuable insights for red teamers:

  1. Identity Attack Vectors

    • Identifies authentication methods for targeted attacks
    • Reveals potential password spray opportunities
    • Highlights federation configurations for SAML attacks
  2. Application Attack Surface

    • Discovers exposed enterprise applications
    • Identifies OAuth abuse opportunities
    • Reveals admin consent endpoints for phishing
  3. Infrastructure Insights

    • Maps Azure services for lateral movement
    • Identifies B2C configurations
    • Discovers potential storage misconfigurations
  4. Security Control Awareness

    • Detects MDI presence for evasion planning
    • Identifies conditional access configurations
    • Reveals authentication requirements

Installation

[pastacode lang=”bash” manual=”%23%20Clone%20the%20repository%0Agit%20clone%20https%3A%2F%2Fgithub.com%2FArcanum-Sec%2Fmsftrecon.git%0Acd%20msftrecon%0A%0A%23%20Create%20virtual%20environment%0Apython3%20-m%20venv%20venv%0Asource%20venv%2Fbin%2Factivate%0A%0A%23%20Install%20requirements%0Apip%20install%20-r%20requirements.txt%0Achmod%20%2Bx%20msftrecon.py” message=”” highlight=”” provider=”manual”/]

Use

Microsoft 365 reconnaissance

Source: https://github.com/Arcanum-Sec/

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce