1200KM / tool
AADInternals — Attack Tool
AADInternals is a PowerShell-based framework for administering, enumerating, and exploiting Azure Active Directory. The tool is publicly available on GitHub.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: AADInternals
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- APT29 · G0016 · Pinned relationship source (relationship--70ceb05c-ed86-4b51-bde0-2455662c30b7)
- Storm-0501 · G1053 · Pinned relationship source (relationship--ff916215-e7dc-410a-919c-83a00eb95dc1)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1003.004 · LSA Secrets · Detection rules & anomalies
- T1048 · Exfiltration Over Alternative Protocol · Detection rules & anomalies
- T1059.001 · PowerShell · Detection rules & anomalies
- T1069.003 · Cloud Groups · Detection rules & anomalies
- T1087.004 · Cloud Account · Detection rules & anomalies
- T1098.005 · Device Registration · Detection rules & anomalies
- T1112 · Modify Registry · Detection rules & anomalies
- T1136.003 · Cloud Account · Detection rules & anomalies
- T1484.002 · Trust Modification · Detection rules & anomalies
- T1526 · Cloud Service Discovery · Detection rules & anomalies
- T1528 · Steal Application Access Token · Detection rules & anomalies
- T1530 · Data from Cloud Storage · Detection rules & anomalies
- T1552.001 · Credentials In Files · Detection rules & anomalies
- T1552.004 · Private Keys · Detection rules & anomalies
- T1556.006 · Multi-Factor Authentication · Detection rules & anomalies
- T1556.007 · Hybrid Identity · Detection rules & anomalies
- T1558.002 · Silver Ticket · Detection rules & anomalies
- T1566.002 · Spearphishing Link · Detection rules & anomalies
- T1589.002 · Email Addresses · Detection rules & anomalies
- T1590.001 · Domain Properties · Detection rules & anomalies
- T1598.003 · Spearphishing Link · Detection rules & anomalies
- T1606.002 · SAML Tokens · Detection rules & anomalies
- T1649 · Steal or Forge Authentication Certificates · Detection rules & anomalies
- T1651 · Cloud Administration Command · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Active Directory Credential Request · DC0084
- Active Directory Object Creation · DC0087
- Active Directory Object Modification · DC0066
- Application Log Content · DC0038
- Cloud Service Enumeration · DC0083
- Cloud Service Modification · DC0069
- Cloud Storage Access · DC0025
- Command Execution · DC0064
- External intelligence (context only) · proposed-external-intelligence-context-only
- File Access · DC0055
- File Creation · DC0039
- File Modification · DC0061
- Group Enumeration · DC0099
- Group Metadata · DC0105
- Group Modification · DC0094
- Logon Session Creation · DC0067
- Logon Session Metadata · DC0088
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Share Access · DC0102
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- Provider-side audit (if lawfully available) · proposed-provider-side-audit-if-lawfully-available
- Script Execution · DC0029
- User Account Authentication · DC0002
- User Account Creation · DC0014
- User Account Metadata · DC0013
- User Account Modification · DC0010
- Web Credential Creation · DC0006
- Web Credential Usage · DC0007
- Windows Registry Key Access · DC0050
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.