ROADTools is a publicly available cloud reconnaissance tool used to enumerate and collect data from Microsoft Entra ID (formerly Azure AD) environments. The provided content states that it automatically gathers data from Azure AD using the Azure AD Graph API, can enumerate Azure AD systems and devices, and leverages valid cloud credentials to perform enumeration through the internal Azure AD Graph API. Microsoft observed the Iranian nation-state actor Peach Sandstorm (HOLMIUM, with overlap to APT33/Elfin/Refined Kitten reporting) using ROADTools during post-compromise reconnaissance after successful password-spray activity, including to access Microsoft Entra ID data and dump that data to a database. The activity was associated with intrusions targeting organizations globally, particularly in the satellite, defense, and to a lesser extent pharmaceutical sectors. High-confidence behavior in the content is limited to Entra ID/Azure AD reconnaissance and data collection using valid credentials; no additional host-based infection vector or standalone malware persistence mechanism is described for ROADTools itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"They used password spray activity, internal reconnaissance with AzureHound or Roadtools..."
26 distinct techniques documented for this family, organized by ATT&CK tactic.
ROADtools operates through legitimate Microsoft APIs and can mimic typical traffic
MITRE: T1078.004: Valid Accounts: Cloud Accounts ... The same user credentials that triggered AADSTS53003 on direct authentication now produced a token with amr: [pwd, rsa] and a deviceid claim.
Mollema published the PowerShell proof-of-concept scripts in the ROADtools repository. The Hacker News found fido_assertion.ps1 and hellopoc.ps1 in the folder on August 6, 2026.
ROADtools operates through legitimate Microsoft APIs and can mimic typical traffic
MITRE: T1078.004: Valid Accounts: Cloud Accounts ... The same user credentials that triggered AADSTS53003 on direct authentication now produced a token with amr: [pwd, rsa] and a deviceid claim.
ROADtx uses stored tokens to perform device registration; the operation creates an Entra ID device entry and issues a device ID, PEM certificate, and private key.
A single roadtx device join command registered a phantom device with a signed Azure AD certificate and private key - no TPM, no hardware verification, no admin approval required. MITRE ATT&CK: T1098.005: Account Manipulation: Device Registration.
Intune does not validate that the device actually exists in on-premises Active Directory or that AD Connect synced it. It trusts the client's self-declared domain membership at enrollment... MITRE: T1556.007: Modify Authentication Process: Hybrid Identity
MITRE: T1098.005: Account Manipulation: Device Registration | T1556.009: Modify Authentication Process: Conditional Access Policies ... The CA policy governing device registration, CA027-001, was in Report-Only mode. It logged what would have happened. It blocked nothing.
ROADtools operates through legitimate Microsoft APIs and can mimic typical traffic
MITRE: T1078.004: Valid Accounts: Cloud Accounts ... The same user credentials that triggered AADSTS53003 on direct authentication now produced a token with amr: [pwd, rsa] and a deviceid claim.
ROADtx uses stored tokens to perform device registration; the operation creates an Entra ID device entry and issues a device ID, PEM certificate, and private key.
The actors abused trusted first-party Microsoft applications to bypass traditional defenses; client IDs were specifically Visual Studio Code or Microsoft Authentication Broker.
Intune does not validate that the device actually exists in on-premises Active Directory or that AD Connect synced it. It trusts the client's self-declared domain membership at enrollment... MITRE: T1556.007: Modify Authentication Process: Hybrid Identity
MITRE: T1098.005: Account Manipulation: Device Registration | T1556.009: Modify Authentication Process: Conditional Access Policies ... The CA policy governing device registration, CA027-001, was in Report-Only mode. It logged what would have happened. It blocked nothing.
Once a target authenticates, the authorization code is exchanged for a refresh token and/or access token, enabling the attacker to make Graph API calls without further user interaction.
Intune does not validate that the device actually exists in on-premises Active Directory or that AD Connect synced it. It trusts the client's self-declared domain membership at enrollment... MITRE: T1556.007: Modify Authentication Process: Hybrid Identity
MITRE: T1098.005: Account Manipulation: Device Registration | T1556.009: Modify Authentication Process: Conditional Access Policies ... The CA policy governing device registration, CA027-001, was in Report-Only mode. It logged what would have happened. It blocked nothing.
They enumerate users, groups, roles, applications and service principals.
“gather walks every interesting object type in the directory (users, groups, service principals, applications, devices, directory roles, role assignments, eligible role assignments, OAuth2 permission grants, administrative units).”
By obtaining a Primary Refresh Token (PRT), an attacker can continuously generate new access tokens in the background without triggering another login prompt. This effectively allows them to operate inside a compromised tenant for extended periods while bypassing MFA controls entirely.
With the access token in hand, the attacker interacts with the Microsoft Graph API endpoint /v1.0/me/messages to extract email messages from the victim's account.
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reconnaissance tool used for data collection from Microsoft Entra ID (Azure AD) environments.
Open-source toolkit commonly used to enumerate and interact with Azure AD/Entra ID, supporting reconnaissance and follow-on actions in cloud identity environments.
Framework used to access and enumerate Microsoft Entra ID data and dump collected information into a database; legitimate admin/red-team utility that can be repurposed for adversary reconnaissance.
An Azure AD-focused enumeration tool that uses valid cloud credentials and the internal Azure AD Graph API.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.