Module 5 Links and Resources Enumerating via Public APIs https://o365blog.com/post/just-looking/ Non-Comprehensive list of Azure domains https://docs.microsoft.com/en-us/azure/security/fundamentals/azure-domains Determine if company is using AzureAD https://login.microsoftonline.com/getuserrealm.srf?login=username@COMPANY.onmicrosoft.com&xml=1 Get Tenant ID Using APIs https://login.microsoftonline.com//.well-known/openid-configuration User List Generation https://hunter.io/ Awesome Azure Pentest https://github.com/Kyuu-Ji/Awesome-Azure-Pentest#enumeration Cloud-Azure PayloadsAllTheThings https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Cloud%20-%20Azure%20Pentest.md AADInternals by @DrAzureAD https://o365blog.com/aadinternals/ MicroBurst (NetSPI) https://github.com/NetSPI/MicroBurst BlobHunter (CyberArk) https://github.com/cyberark/blobhunter Cloud Enum https://github.com/initstring/cloud_enum MFASweep https://github.com/dafthack/MFASweep O365Recon https://github.com/nyxgeek/o365recon AzureHound https://github.com/BloodHoundAD/AzureHound Custom Bloodhound Queries for Azure https://github.com/hausec/Bloodhound-Custom-Queries