ATT&CKSoftwareAADInternals

AADInternals

S0677

Tool.View on attack.mitre.org

About this tool

AADInternals is a PowerShell-based framework for administering, enumerating, and exploiting Azure Active Directory. The tool is publicly available on GitHub.

Techniques used24

Procedure examples24

TechniqueProcedure example
T1003.004
LSA Secrets

AADInternals can dump secrets from the Local Security Authority.

T1048
Exfiltration Over Alternative Protocol

AADInternals can directly download cloud user data such as OneDrive files.

T1059.001
PowerShell

AADInternals is written and executed via PowerShell.

T1069.003
Cloud Groups

AADInternals can enumerate Azure AD groups.

T1087.004
Cloud Account

AADInternals can enumerate Azure AD users.

T1098.005
Device Registration

AADInternals can register a device to Azure AD.

T1112
Modify Registry

AADInternals can modify registry keys as part of setting a new pass-through authentication agent.

T1136.003
Cloud Account

AADInternals can create new Azure AD users.

T1484.002
Trust Modification

AADInternals can create a backdoor by converting a domain to a federated domain which will be able to authenticate any user across the tenant. AADInternals can also modify DesktopSSO information.

T1526
Cloud Service Discovery

AADInternals can enumerate information about a variety of cloud services, such as Office 365 and Sharepoint instances or OpenID Configurations.

T1528
Steal Application Access Token

AADInternals can steal users’ access tokens via phishing emails containing malicious links.

T1530
Data from Cloud Storage

AADInternals can collect files from a user’s OneDrive.

T1552.001
Credentials In Files

AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine.

T1552.004
Private Keys

AADInternals can gather encryption keys from Azure AD services such as ADSync and Active Directory Federated Services servers.

T1556.006
Multi-Factor Authentication

The AADInternals `Set-AADIntUserMFA` command can be used to disable MFA for a specified user.

View all 24 procedure examples

Groups that use it2

Campaigns0

None recorded.

References2

  1. AADInternals Documentation Open source
    Dr. Nestori Syynimaa. (2018, October 25). AADInternals. Retrieved February 18, 2022.
  2. AADInternals Github Open source
    Dr. Nestori Syynimaa. (2021, December 13). AADInternals. Retrieved February 1, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.