Cloud
ROADtools
Framework for collecting and exploring Microsoft Entra directory data you are allowed to read.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
Authorized tenants only. Not for directories you do not administer or have a contract to review.
When
An authorized review of one tenant, when you need users, groups, roles, and app relationships in a local view.
How
Use it only against a tenant in the written scope. This entry is descriptive and does not include collection commands.
Why
Relationships in Entra are easier to explain when they are in one dataset the engagement owns.
Commands & usage
# Descriptive only. No collection commands on this page.
# Scope the tenant first. See the Identity, SSO and Entra ID module.
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Tags
Related in Cloud
Pacu
AWS exploitation framework for post-compromise cloud assessment.
Prowler
Cloud security best-practice assessment tool (AWS/Azure/GCP).
ScoutSuite
Multi-cloud security auditing tool producing HTML reports.
CloudMapper
Network visualization and analysis for AWS environments.
enumerate-iam
Enumerates permissions for AWS access keys by trying API calls.
AWS CLI / Azure CLI / gcloud
Official cloud CLIs — primary interface for cloud assessments.