MSFTRecon is a specialized reconnaissance tool designed for red teamers and security professionals to map and analyze Microsoft 365 and Azure tenant infrastructures.
Its primary focus is on identifying potential security misconfigurations and attack vectors without requiring authentication, making it an invaluable asset for penetration testing and security assessments.
--gov
) and China-specific Azure instances (--cn
).To install MSFTRecon:
bash# Clone the repository
git clone https://github.com/Arcanum-Sec/msftrecon.git
cd msftrecon
# Set up virtual environment
python3 -m venv venv
source venv/bin/activate
# Install dependencies
pip install -r requirements.txt
chmod +x msftrecon.py
./msftrecon.py -d example.com
./msftrecon.py -d example.com -j
./msftrecon.py -d example.gov --gov
./msftrecon.py -d example.cn --cn
text[+] Target Organization:
Tenant Name: Contoso
Tenant ID: 1234abcd-1234-abcd-1234-1234abcd1234
[+] Federation Information:
Namespace Type: Managed
Brand Name: Contoso
Cloud Instance: microsoftonline.com
[+] Identity Insights:
* Cloud-only authentication detected.
MSFTRecon is intended strictly for legal security assessments. Users must obtain proper authorization before using this tool. The authors disclaim responsibility for misuse or damages caused by its application.
By providing detailed insights into Microsoft 365 and Azure infrastructures, MSFTRecon empowers security professionals to proactively identify vulnerabilities and enhance organizational defenses.
Helix is a modern, terminal-based text editor designed for developers seeking speed, efficiency, and advanced…
Azure-SecOps is a critical framework that integrates security tools and operational processes to ensure robust…
Tauri is an innovative framework designed to create lightweight, high-performance desktop applications. It empowers developers…
Linkook is a powerful Open Source Intelligence (OSINT) tool designed to uncover interconnected social media…
Lapce is a modern, open-source code editor designed for speed, efficiency, and extensibility. Built entirely…
The recent leak of Black Basta’s internal communications, spanning over 200,000 chat messages, has provided…