TeamFiltration is an open-source tool for Microsoft Entra ID and Microsoft 365 designed for enumeration, password spraying, and exfiltration. The provided content describes it as a penetration testing framework publicly released by Melvin "Flangvik" Langvik in August 2022 at DEF CON, and notes that defenders detect it via characteristic user-agent strings in Azure/M365 sign-in and audit logs. TeamFiltration has been linked to large-scale account takeover activity against Microsoft cloud environments, including a campaign reported by Proofpoint as UNK_SneakyStrike. In that activity, attackers used TeamFiltration together with the Microsoft Teams API and geographically distributed AWS infrastructure to enumerate users and conduct password spraying against Microsoft Entra ID accounts. The campaign targeted more than 80,000 users across hundreds of organizations or nearly 100 cloud tenants beginning in December 2024. Successful compromises resulted in access to Microsoft cloud resources and native applications including Microsoft Teams, OneDrive, and Outlook. High-confidence indicators mentioned in the content include TeamFiltration-specific user-agent strings observed in Entra ID sign-in and audit logs.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
"All 7 successfully compromised accounts were unmanaged functional/service accounts" and the attacker authenticated to Microsoft Teams after password spraying.
"All 7 successfully compromised accounts were unmanaged functional/service accounts" and the attacker authenticated to Microsoft Teams after password spraying.
This unexpected behavior indicates user agent spoofing and is meant to obfuscate the real client or device from which the intrusion originated.
"...high volume of failed interactive or non-interactive authentication attempts... indicative of password spraying, credential stuffing, or password guessing."
TeamFiltration is designed for “enumerating, spraying, exfiltrating, and backdooring” Entra ID accounts and “allows an operator to validate email accounts [and] test common or targeted passwords across enumerated accounts.”
TeamFiltration's Exfiltrate module "harvests email, Teams chats, OneDrive/SharePoint files," and Microsoft Office access was identified as "Email and calendar exfiltration (Outlook REST)."
TeamFiltration can collect "Teams chats" and accessed Microsoft Teams across all seven compromised accounts.
“Across most of the compromised accounts, the threat actor leveraged the foothold to access Microsoft Office, OneDrive, and Teams, potentially indicative of data harvesting and exfiltration. That said, sign-in events alone cannot be taken as evidence of exfiltration.”
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An attacker tool used against Microsoft 365/Azure environments for account enumeration and password spraying; detectable via characteristic user-agent strings in sign-in/audit telemetry.
Open-source penetration testing framework abused for automated account takeover, credential harvesting, and lateral movement in cloud environments.
TeamFiltration is an open-source penetration testing tool that has been abused by attackers to conduct account takeover campaigns, specifically targeting Microsoft Entra ID accounts through user enumeration and password spraying.
An open-source tool used to enumerate Entra ID/M365 tenants, perform password spraying, and facilitate data access/exfiltration activities; detectable via characteristic user-agent strings in sign-in/audit logs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.