Dr. Nestori Syynimaa. (2018, October 25). AADInternals. Retrieved February 18, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.004 LSA Secrets |
ToolAADInternals | AADInternals can dump secrets from the Local Security Authority. |
| T1048 Exfiltration Over Alternative Protocol |
ToolAADInternals | AADInternals can directly download cloud user data such as OneDrive files. |
| T1059.001 PowerShell |
ToolAADInternals | AADInternals is written and executed via PowerShell. |
| T1069.003 Cloud Groups |
ToolAADInternals | AADInternals can enumerate Azure AD groups. |
| T1087.004 Cloud Account |
ToolAADInternals | AADInternals can enumerate Azure AD users. |
| T1098.005 Device Registration |
ToolAADInternals | AADInternals can register a device to Azure AD. |
| T1112 Modify Registry |
ToolAADInternals | AADInternals can modify registry keys as part of setting a new pass-through authentication agent. |
| T1136.003 Cloud Account |
ToolAADInternals | AADInternals can create new Azure AD users. |
| T1484.002 Trust Modification |
ToolAADInternals | AADInternals can create a backdoor by converting a domain to a federated domain which will be able to authenticate any user across the tenant. AADInternals can also modify DesktopSSO information. |
| T1526 Cloud Service Discovery |
ToolAADInternals | AADInternals can enumerate information about a variety of cloud services, such as Office 365 and Sharepoint instances or OpenID Configurations. |
| T1528 Steal Application Access Token |
ToolAADInternals | AADInternals can steal users’ access tokens via phishing emails containing malicious links. |
| T1552.001 Credentials In Files |
ToolAADInternals | AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine. |
| T1552.004 Private Keys |
ToolAADInternals | AADInternals can gather encryption keys from Azure AD services such as ADSync and Active Directory Federated Services servers. |
| T1558.002 Silver Ticket |
ToolAADInternals | AADInternals can be used to forge Kerberos tickets using the password hash of the AZUREADSSOACC account. |
| T1566.002 Spearphishing Link |
ToolAADInternals | AADInternals can send "consent phishing" emails containing malicious links designed to steal users’ access tokens. |
| T1589.002 Email Addresses |
ToolAADInternals | AADInternals can check for the existence of user email addresses using public Microsoft APIs. |
| T1590.001 Domain Properties |
ToolAADInternals | AADInternals can gather information about a tenant’s domains using public Microsoft APIs. |
| T1598.003 Spearphishing Link |
ToolAADInternals | AADInternals can send phishing emails containing malicious links designed to collect users’ credentials. |
| T1606.002 SAML Tokens |
ToolAADInternals | AADInternals can be used to create SAML tokens using the AD Federated Services token signing certificate. |
| T1649 Steal or Forge Authentication Certificates |
ToolAADInternals | AADInternals can create and export various authentication certificates, including those associated with Azure AD joined/registered devices. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.