EntraTrace is a defensive security research tool for documenting and identifying the observable behavior of offensive tooling targeting Microsoft Entra ID.
The project builds a automatic knowledge base around tools such as AzureHound, AADInternals, O365Enum, PingCastle, and others, with a focus on the UserAgent and API artifacts they generate.
Project Status
🚧 Early development
The project is actively being developed. Data, tooling coverage, and functionality will evolve over time.
Contributions, research, corrections, and additional tool analysis are welcome.
What does it track?
EntraTrace focuses on information that can be useful to defenders, including:
- 🔎 API endpoints — Microsoft Graph, Azure AD Graph and other API endpoints accessed by tooling
- 🕵️ User agents — HTTP user agents associated with offensive tools
- 🛡️ Detection opportunities — Data that can support detection engineering, hunting, and incident response
The goal is to make offensive tooling behavior easier for defensive teams to understand and turn into actionable information.
Tool Profiles
| Tool | Unique APIs | Unique API calls | UserAgents |
|---|---|---|---|
| aadinternals | 4 | 110 | 18 |
| AzureHound | 2 | 28 | 0 |
| Graphpython | 3 | 119 | 17 |
| GraphRunner | 4 | 67 | 21 |
| GraphSpy | 2 | 38 | 2 |
| MFASweep | 4 | 17 | 11 |
| MicroBurst | 3 | 78 | 0 |
| MSOLSpray | 1 | 1 | 0 |
| o365enum | 1 | 1 | 2 |
| o365spray | 1 | 1 | 2 |
| pingcastle | 3 | 14 | 1 |
| PowerZure | 3 | 29 | 0 |
| ROADtools | 4 | 434 | 7 |
| ropci | 3 | 15 | 0 |
| Stormspotter | 3 | 4 | 0 |
| TeamFiltration | 3 | 62 | 2 |
| TokenSmith | 2 | 8 | 0 |
| TokenTactics | 4 | 8 | 16 |
| TokenTacticsV2 | 4 | 30 | 23 |
Why?
Offensive security tools are frequently used to assess and attack identity environments. Understanding how those tools interact with Entra ID can help defenders identify their use, investigate suspicious activity, and improve detection coverage.
EntraTrace aims to bridge the gap between offensive tooling research and defensive security operations.
Use Cases
EntraTrace can be used to:
- Build detections for known offensive security tools
- Develop Microsoft Sentinel / SIEM hunting queries
- Investigate suspicious Entra ID and Microsoft Graph activity
- Identify tooling during incident response
- Research the behavior of offensive identity tooling
- Improve defensive visibility into identity attack techniques
AI-Assisted Development
🤖 EntraTrace is developed with the assistance of AI. AI is used throughout the development and research process, with human review and validation of the resulting work.
Local Deployment
The repository is updated daily, but local deployment is supported. To run locally from the repository root with Python. Use the built-in help output to confirm the available options before running them.
⚠️ - Running the script locally may result in security alerts as repos containing offensive tools are downloaded locally to extract the information needed to create a profile.
# Extract API behavior from a repo or refresh all profile entries
python .\Scripts\ExtractToolBehavior.py --all-profiles --output-dir .\Profiles
# Export tool user agents from YAML profiles into a CSV
python .\Scripts\SummarizeUserAgents.py --profiles-dir .\Profiles --output .\Indicator Lists\UserAgents.csv
SummarizeUserAgents.pyexports user-agent data from profile YAML files into a hunting CSV.ExtractToolBehavior.pyreads repository URLs fromProfiles\Tools.txtwhen present, and otherwise falls back to everyrepository_urlfound in the YAML profile files in the output directory.- Run either script with
-hor--helpto view the full parameter set and behavior.
Related Content
- Investigating Microsoft Graph Activity Logs
- GraphApiAuditEvents: The new Graph API Logs
- Detect threats using Microsoft Graph activity logs - Part 1 by Fabian Bader
- Detect threats using Microsoft Graph activity logs - Part 2 by Fabian Bader
- Detect threats using GraphAPIAuditEvents - Part 3 by Fabian Bader
- Everything you need to know about the MicrosoftGraphActivityLogs by Invictus IR
- The Missing Link: AADGraphActivityLogs Finally Arrives by Invictus IR
Comments