Gerenios / AADInternals

AADInternals PowerShell module for administering Azure AD and Office 365
http://aadinternals.com/aadinternals
MIT License
1.3k stars 217 forks source link

Add support for user dynamic group abuse (Get-DynamicAbusableGroups) #93

Closed sapirxfed closed 5 days ago

sapirxfed commented 4 months ago

This function returns Entra ID groups with user dynamic membership rule that contains attributes that can be modified by users. Related articles: https://medium.com/r3d-buck3t/abusing-dynamic-groups-in-azuread-part-1-ff12e328c8c0 https://www.mnemonic.io/resources/blog/abusing-dynamic-groups-in-azure-ad-for-privilege-escalation/ Usage: image