LogoClawIndex
CasesSkillsAbout
LogoClawIndex

auditing-entra-id-with-aadinternals - Audit Microsoft Entra ID and AD FS using AADInternals.

Perform Microsoft Entra ID tenant reconnaissance, access-token acquisition, and federation backdoor testing using the AADInternals PowerShell toolkit.

Tags

Updated: 2026-09-23

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Perform unauthenticated tenant reconnaissance
  • Enumerate candidate user accounts
  • Acquire Microsoft API access tokens
  • Enumerate directory users and privileges
  • Inspect AD FS signing certificates
  • Test federation backdoor configurations
  • Forge SAML authentication tokens

Inputs

  • Target domain name
  • Candidate UPN list
  • User credentials
  • Global Administrator account credentials
  • Target user ImmutableID
  • AD FS server access

Outputs

  • Tenant reconnaissance details
  • Cached Microsoft API access tokens
  • Directory enumeration results
  • Exported AD FS signing certificate PFX file
  • Forged SAML authentication token

Requirements

  • Written authorization for identity attack testing
  • Windows host with PowerShell 5.1+ or PowerShell 7
  • AADInternals PowerShell module
  • Global Administrator privileges for backdoor testing

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.
aadinternals
entra-id
azure-ad
saml-token-forgery
federation-backdoor
token-manipulation
adfs
red-team
Perform unauthenticated tenant reconnaissance
Enumerate candidate user accounts
Acquire Microsoft API access tokens
Enumerate directory users and privileges
Target domain name
Candidate UPN list
User credentials
Tenant reconnaissance details
Cached Microsoft API access tokens
Directory enumeration results