ATT&CKReferencesAADInternals Documentation

AADInternals Documentation

Dr. Nestori Syynimaa. (2018, October 25). AADInternals. Retrieved February 18, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples20

TechniqueUsed byProcedure example
T1003.004
LSA Secrets
ToolAADInternals

AADInternals can dump secrets from the Local Security Authority.

T1048
Exfiltration Over Alternative Protocol
ToolAADInternals

AADInternals can directly download cloud user data such as OneDrive files.

T1059.001
PowerShell
ToolAADInternals

AADInternals is written and executed via PowerShell.

T1069.003
Cloud Groups
ToolAADInternals

AADInternals can enumerate Azure AD groups.

T1087.004
Cloud Account
ToolAADInternals

AADInternals can enumerate Azure AD users.

T1098.005
Device Registration
ToolAADInternals

AADInternals can register a device to Azure AD.

T1112
Modify Registry
ToolAADInternals

AADInternals can modify registry keys as part of setting a new pass-through authentication agent.

T1136.003
Cloud Account
ToolAADInternals

AADInternals can create new Azure AD users.

T1484.002
Trust Modification
ToolAADInternals

AADInternals can create a backdoor by converting a domain to a federated domain which will be able to authenticate any user across the tenant. AADInternals can also modify DesktopSSO information.

T1526
Cloud Service Discovery
ToolAADInternals

AADInternals can enumerate information about a variety of cloud services, such as Office 365 and Sharepoint instances or OpenID Configurations.

T1528
Steal Application Access Token
ToolAADInternals

AADInternals can steal users’ access tokens via phishing emails containing malicious links.

T1552.001
Credentials In Files
ToolAADInternals

AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine.

T1552.004
Private Keys
ToolAADInternals

AADInternals can gather encryption keys from Azure AD services such as ADSync and Active Directory Federated Services servers.

T1558.002
Silver Ticket
ToolAADInternals

AADInternals can be used to forge Kerberos tickets using the password hash of the AZUREADSSOACC account.

T1566.002
Spearphishing Link
ToolAADInternals

AADInternals can send "consent phishing" emails containing malicious links designed to steal users’ access tokens.

T1589.002
Email Addresses
ToolAADInternals

AADInternals can check for the existence of user email addresses using public Microsoft APIs.

T1590.001
Domain Properties
ToolAADInternals

AADInternals can gather information about a tenant’s domains using public Microsoft APIs.

T1598.003
Spearphishing Link
ToolAADInternals

AADInternals can send phishing emails containing malicious links designed to collect users’ credentials.

T1606.002
SAML Tokens
ToolAADInternals

AADInternals can be used to create SAML tokens using the AD Federated Services token signing certificate.

T1649
Steal or Forge Authentication Certificates
ToolAADInternals

AADInternals can create and export various authentication certificates, including those associated with Azure AD joined/registered devices.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.