Skip to content

Instantly share code, notes, and snippets.

View invictus-korstiaan's full-sized avatar

Invictus-Korstiaan invictus-korstiaan

View GitHub Profile
@invictus-korstiaan
invictus-korstiaan / Invoke-GraphRecon.csv
Last active October 27, 2023 13:34
Invoke-GraphRecon
Log source Indicator
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/search/query
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/servicePrincipals
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/users/
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/users/{ID}
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/organization
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/servicePrincipals(appId='{AppID}')/appRoleAssignedTo
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/applications
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/servicePrincipals/{ID}
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/servicePrincipals?$skiptoken={Token}
Log source Indicator
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/search/query
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/users/{ID}
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/organization
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/servicePrincipals(appId='{AppId}')/appRoleAssignedTo
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/applications
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/servicePrincipals/{ID}
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/servicePrincipals?$skiptoken={Token}
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/servicePrincipals
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/groups/{GroupID}/members
@invictus-korstiaan
invictus-korstiaan / Invoke-GraphOpenInboxFinder.csv
Created October 27, 2023 08:48
Invoke-GraphOpenInboxFinder
Log source Indicator
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/search/query
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/users/{Email}/mailFolders/Inbox/messages
@invictus-korstiaan
invictus-korstiaan / Get-SharePointSiteURLs.csv
Created October 27, 2023 08:54
Get-SharePointSiteURLs
Log source Indicator
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/search/query
Log source Indicator
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/groups
Log source Indicator
MicrosoftGraphActivityLogs https://graph.microsoft.com/beta/roleManagement/directory/estimateAccess
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/groups
Log source Indicator
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/groups/{ID}/members
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/groups?=securityEnabled%20eq%20true
Log source Indicator
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/users
@invictus-korstiaan
invictus-korstiaan / Invoke-InjectOAuthApp.csv
Last active October 27, 2023 09:35
Invoke-InjectOAuthApp
Log source Indicator
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/applications/{ID}/addPassword
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/applications
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/servicePrincipals{ID}
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/servicePrincipals?$skiptoken={TOKEN}
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/servicePrincipals
Entra ID Audit Log Update application
Entra ID Audit Log Update application – Certificates and secrets management
Entra ID Audit Log Add application
@invictus-korstiaan
invictus-korstiaan / Invoke-SecurityGroupCloner.csv
Created October 27, 2023 09:29
Invoke-SecurityGroupCloner
Log source Indicator
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/groups/{ID}/members
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/groups/{ID}/members/$ref
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/groups?=securityEnabled%20eq%20true
MicrosoftGraphActivityLogs https://graph.microsoft.com/v1.0/me
Entra ID Audit Log Add member to group
Entra ID Audit Log Add group