AADInternals is a PowerShell-based offensive and research toolkit focused on Microsoft Entra ID and hybrid identity infrastructure, particularly Azure AD Connect, Pass-through Authentication, and Active Directory Federation Services environments. It is capable of harvesting unsecured credentials from Azure AD-related services on local systems, extracting encryption keys from identity infrastructure components such as ADSync and AD FS servers, and dumping Local Security Authority secrets on Windows hosts. The toolkit also supports manipulation of Windows registry settings as part of configuring or implanting a new Pass-through Authentication agent, including techniques associated with PTA credential interception on Azure AD Connect servers. In addition to credential and key access, AADInternals includes reconnaissance functionality to validate user email addresses through public Microsoft APIs and can be used for consent-phishing operations that send malicious links intended to steal users’ access tokens. Its capabilities make it particularly relevant to post-compromise abuse of hybrid identity environments and Tier 0 identity assets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
The implication of this attack was that the threat actors were able to log in and impersonate any Microsoft 365 (M365) user and bypass all requirements for MFA as well as bypass any need to enter a valid password.
Step 6 - Cloud Pivot (Storm-0501 specific) T1078.004, T1098.001, T1098.003, T1484.002, T1537 | Affiliate Compromises Microsoft Entra Connect Sync accounts or hijacks on-prem sessions with cloud admin privileges (no MFA).
Calling an organization’s help desk and socially engineering the help desk to reset the user’s password and/or change/add a multi-factor authentication token/factor... Addition of MFA methods to existing users.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
They use these tools to perform enumeration of the victim’s Azure environment, backdooring active directory, various persistence techniques and lateral movement.
AADConnect PS > Import-Module AADInternals AADConnect PS > Install-AADIntPTASpy 1. TA injects malicious DLL in “AzureADConnectAuthenticationAgentService”
The implication of this attack was that the threat actors were able to log in and impersonate any Microsoft 365 (M365) user and bypass all requirements for MFA as well as bypass any need to enter a valid password.
Step 6 - Cloud Pivot (Storm-0501 specific) T1078.004, T1098.001, T1098.003, T1484.002, T1537 | Affiliate Compromises Microsoft Entra Connect Sync accounts or hijacks on-prem sessions with cloud admin privileges (no MFA).
To be a little sneakier, let’s now remove the service and agent completely.
The implication of this attack was that the threat actors were able to log in and impersonate any Microsoft 365 (M365) user and bypass all requirements for MFA as well as bypass any need to enter a valid password.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Using Mimikatz, the attacker exfiltrates the PRT token from memory (LSASS).
A legacy Entra ID endpoint kept alive for Office 2013 clients lets attackers spray passwords past Smart Lockout, confirm valid credentials on MFA-protected accounts, and leave only partial logs behind.
When executed, ConvertTo-AADIntBackdoor modifies the federation settings of a domain by adding or changing the federation configuration to allow an attacker to control the authentication process. This manipulation enables the creation of security tokens that can impersonate any user within the Azure AD tenant. Annotations ID Technique Tactic T1212 Exploitation for Credential Access Persistence
Token Theft ROADtools AADInternals TokenTactics PRT theft OAuth / Device Code Device code phishing Illicit consent grant
Pass-the-Cookie ... involves directly stealing the PRT cookie from the compromised local AAD user ... to exfiltrate a PRT cookie associated with a compromised local AAD user and impersonate their identity.
AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine... Agent Tesla has the ability to extract credentials from configuration or support files... APT33 has used a variety of publicly available tools like LaZagne to gather credentials.
For identity-based persistence, Octo Tempest targets federated identity providers using tools like AADInternals to federate existing domains, or spoof legitimate domains by adding and then federating new domains.
one of the techniques utilised by the threat actors to gain control of a victim's Azure Active Directory (AAD) was to create an AAD backdoor through identity federation.
Octo Tempest is a financially motivated collective... known for launching wide-ranging campaigns that prominently feature adversary-in-the-middle (AiTM) techniques... Navigate to a site configured with a fake login portal using an adversary-in-the-middle toolkit.
Essentially, to generate fake events and send them into Azure sign-in logs, the attacker needs to get a service access token... The attacker then use this token to get a blob storage URL with a SAS token... uploads the “fake” events to blob storage.
The way that AD FS stores its configuration encryption key involves the use of a Distributed Key Manager (DKM) container which is located in the DC... To summarize the LDAP Object query... thumbnailPhoto attribute is AD FS’ DKM LDAP query example to retrieve the AD FS DKM
The requests covered directory-wide discovery targets: ... servicePrincipals ... groups ... directoryRoles ... applications ... devices ... users ... oauth2PermissionGrants ... tenantDetails ... This pattern is consistent with automated tenant mapping.
“ROADrecon's gather command uses aiohttp by default and walks every directory object type” and produces “Bulk enumeration across every object type ROADrecon knows.”
The requests covered directory-wide discovery targets: ... servicePrincipals ... applicationRefs / other app objects ... applications ... oauth2PermissionGrants ... app role assignments.
Notably toolkits like ROADtools and AADInternals use this API to gather deep insights into the tenant... Gathering information for a whole tenant requires a lot of requests to different endpoints... I created a hunting query which you can use to find ROADtools based on the endpoints the default gather parameter requests.
Octo Tempest is a financially motivated collective... known for launching wide-ranging campaigns that prominently feature adversary-in-the-middle (AiTM) techniques... Navigate to a site configured with a fake login portal using an adversary-in-the-middle toolkit.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PowerShell-based tool executed via PowerShell.
A PowerShell-based tool executed via PowerShell.
A post-exploitation tool that can gather encryption keys from Azure AD-related services including ADSync and AD FS servers.
Tool capable of collecting unsecured Azure AD service credentials from local systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.