Reposted by @zh54321.bsky.socialCompass Security @compass-security.com · 24/03/2026Foreign enterprise apps can expose your Entra ID tenant. Today, we release part 1 of our 4-part weekly series on common Entra ID pitfalls and how to detect them with EntraFalcon. Learn how external apps can lead to data access or worse: blog.compass-security.com/2026/03/comm... 032
Reposted by @zh54321.bsky.socialCompass Security @compass-security.com · 17/03/2026EntraFalcon update 🚀 The new Security Findings Report turns Entra ID enumeration into actionable findings with 60+ checks and colorful charts. Read Chrigi's @zh54321.bsky.social blog and try the tool now on your tenant! blog.compass-security.com/2026/03/from... #EntraID #CloudSecurity #EntraFalcon 044
Reposted by @zh54321.bsky.socialCompass Security @compass-security.com · 29/04/2025Tired of sifting through Entra ID manually? EntraFalcon is a PowerShell tool that flags risky objects configs & privileged role assignments with ⚡ Scoring model 📊 HTML reports 🔒 No Graph API consent hassle. Get it now: blog.compass-security.com/2025/04/intr... #EntraID #IAM 065
zh54321.bsky.social @zh54321.bsky.social · 18/01/2025Simpe PowerShell WebServer - Starts an HTTP server on any IP and port you specify. - Handles errors gracefully - Can be stopped manually with Ctrl+C or automatically after a timeout. - Easy to integrate in your scripts - 1 File - PS 5.1 & PS 7.4 #powershell github.com/zh54321/Powe...github.comGitHub - zh54321/PowerShell_HttpServer: Simple PowerShell HTTP Server (no dependencies, single file, PowerShell 5.1/7)Simple PowerShell HTTP Server (no dependencies, single file, PowerShell 5.1/7) - zh54321/PowerShell_HttpServer 210
zh54321.bsky.social @zh54321.bsky.social · 25/12/2024Pure PowerShell PoC of the Entra ID Conditional Access Compliant Device bypass. github.com/zh54321/PoCE... Credits to the researchers @_dirkjan , @TEMP43487580 . And to @JumpsecLabs for the write-up (labs.jumpsec.com/tokensmith-b...) #entra #Azure #Intune #pentestgithub.comGitHub - zh54321/PoCEntraDeviceComplianceBypass: Simple pure PowerShell POC to bypass Entra / Intune Compliance Conditional Access PolicySimple pure PowerShell POC to bypass Entra / Intune Compliance Conditional Access Policy - zh54321/PoCEntraDeviceComplianceBypass 011
zh54321.bsky.social @zh54321.bsky.social · 26/11/2024🚀 Just released EntraTokenAid: a pure PowerShell module for MS Entra OAuth auth. 🔑 Auth as AzureCLI (or other clients), get access/refresh tokens for APIs like MS Graph / ARM etc. ✨ Lightweight, portable, no dependencies! 👉 github.com/zh54321/Entr... #Entra #Azure #pentesting #entraidgithub.comGitHub - zh54321/EntraTokenAid: A pure PowerShell solution for Entra OAuth authentication, enabling easy retrieval of access and refresh tokensA pure PowerShell solution for Entra OAuth authentication, enabling easy retrieval of access and refresh tokens - zh54321/EntraTokenAid 010