Cloud
GraphRunner
PowerShell toolkit for exploring what a Microsoft Graph identity can see in an authorized review.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
Authorized identities and tenants only. Do not use found tokens.
When
You need to understand Graph permissions already granted to an identity the engagement is allowed to review.
How
Use the name in a report when an inventory of Graph access is in scope. This page does not include commands or tokens.
Why
Application and delegated Graph permissions are a common place for overly broad access.
Commands & usage
# Descriptive only. No commands and no tokens on this page.
# See the Identity, SSO and Entra ID module for how to scope the work.
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Tags
Related in Cloud
Pacu
AWS exploitation framework for post-compromise cloud assessment.
Prowler
Cloud security best-practice assessment tool (AWS/Azure/GCP).
ScoutSuite
Multi-cloud security auditing tool producing HTML reports.
CloudMapper
Network visualization and analysis for AWS environments.
enumerate-iam
Enumerates permissions for AWS access keys by trying API calls.
AWS CLI / Azure CLI / gcloud
Official cloud CLIs — primary interface for cloud assessments.