Skip to content
View nicolonsky's full-sized avatar

Highlights

  • Pro

Block or report nicolonsky

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

EAA is a curated catalog of techniques and real-world cases involving abuse of local AI agents through their runtime, configuration, state, tools, and inherited authority.

Python 92 5 Updated Sep 16, 2026

Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MITRE ATT&CK mapping.

PowerShell 176 26 Updated Sep 15, 2026

Azure Function that delivers secrets to managed endpoints using mutual TLS. Devices authenticate with their machine certificate, the function validates the cert chain against a trusted Root CA, the…

PowerShell 1 Updated Sep 14, 2026

Microsoft Sentinel SIEM Log Source Analyzer

PowerShell 29 Updated Sep 12, 2026

SOCAutomators Substack blog companion — threat research, DBIR analysis, and security operations content

21 2 Updated Jun 3, 2026

Lab content for the ExpertsLive Denmark 2026 Identity Masterclass

TypeScript 116 57 Updated Feb 26, 2026

A .NET Framework 4.0 Windows Agent

C# 561 132 Updated Aug 11, 2026

Dump Azure AD Connect credentials for Azure AD and Active Directory

C# 811 100 Updated Aug 26, 2025
HTML 27 3 Updated Sep 15, 2026

Collection of different Azure/Entra focused solutions (Deployable templates, Function Apps, etc)

PowerShell 81 4 Updated Apr 12, 2026
40 7 Updated Dec 11, 2024

M365/Azure adversary simulation tool that generates realistic attack telemetry to help blue teams improve their detection and response capabilities.

Python 332 22 Updated Sep 2, 2026

Research into Undocumented Behavior of Azure AD Refresh Tokens

Python 370 44 Updated Feb 23, 2024

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on a VM.

PowerShell 9,060 1,117 Updated Jun 23, 2026

TokenSmith generates Entra ID access & refresh tokens on offensive engagements. It is suitable for both covert adversary simulations and penetration tests with the tokens generated working out of t…

Go 422 51 Updated Jan 23, 2025

Simple pure PowerShell POC to bypass Entra / Intune Compliance Conditional Access Policy

PowerShell 170 17 Updated Nov 17, 2025
PowerShell 128 18 Updated Jun 17, 2025

Repository hosting a static list of Microsoft First party apps and Graph permissions that's updated daily

PowerShell 244 34 Updated Sep 22, 2026

PowerShell framework to assess Azure security

PowerShell 1,294 181 Updated Oct 18, 2025

A collection of Azure AD/Entra tools for offensive and defensive security purposes

Python 2,723 395 Updated Aug 5, 2026

A framework for developing alerting and detection strategies for incident response.

908 143 Updated Sep 8, 2025

Cloud-native SIEM for intelligent security analytics for your entire enterprise.

Python 6,141 3,821 Updated Sep 22, 2026

Microsoft Threat Intelligence

Python 215 42 Updated Sep 21, 2026

Passkeys/FIDO2/WebAuthn .NET Library for Windows Desktop and CLI Applications

C# 61 13 Updated Aug 23, 2026

A curated list of awesome tools, research, papers and other projects related to password cracking and password security.

1,088 93 Updated Sep 6, 2026
PowerShell 49 34 Updated Feb 3, 2025

A code sample demonstrating how to use Entra Verified ID's functionality to issue and consume verifiable credentials in node.

JavaScript 24 29 Updated Sep 26, 2024
Next