detecting-entra-offensive-tools-in-graph-logs
brianmcgillion/re-benchmarkHunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics using KQL to fingerprint offensive Entra ID enumeration tools…
Scores out of 100 · grade B+
2026-08-21Works
40% of the score100/100
- Loads cleanly: valid frontmatter, required fields present, no dangling references.
Maintained
25% of the score94/100
- no commits in the last 12 weeks
- no license file
Adopted
20% of the score0/100
- No install or star signal yet.
Documented
15% of the score100/100
- 1,265 words with worked examples.
- Ships 4 bundled files.
Install
npx skills add brianmcgillion/re-benchmark/detecting-entra-offensive-tools-in-graph-logsWhat the check found
| Finding | What it means |
|---|---|
| No license | The repository ships no license file, so the reuse terms are unclear. |
What it says it does
Hunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics using KQL to fingerprint offensive Entra ID enumeration tools such as ROADtools, AADInternals, and AzureHound, including User-Agent signatures, roadrecon endpoint sweeps, and sign-in correlation. Use when investigating suspicious Microsoft Graph API activity, Entra ID reconnaissance, or building Sentinel analytics rules to detect these tools.
Also in brianmcgillion/re-benchmark
| Artifact | Score | What the check found | Type | Reach | Last commit |
|---|---|---|---|---|---|
| auditing-kubernetes-rbac-privilege-escalationbrianmcgillion/re-benchmark | No license | Skill | no signal | today | |
| building-attack-pattern-library-from-cti-reportsbrianmcgillion/re-benchmark | No license | Skill | no signal | today | |
| building-identity-governance-lifecycle-processbrianmcgillion/re-benchmark | No license | Skill | no signal | today | |
| analyzing-ios-app-security-with-objectionbrianmcgillion/re-benchmark | No license | Skill | no signal | today | |
| analyzing-apt-group-with-mitre-navigatorbrianmcgillion/re-benchmark | No license | Skill | no signal | today | |
| analyzing-browser-forensics-with-hindsightbrianmcgillion/re-benchmark | No license | Skill | no signal | today |
Other data & analytics skills
Browse all| Artifact | Score | What the check found | Category | Reach | Last commit |
|---|---|---|---|---|---|
| data-context-extractoranthropics/knowledge-work-plugins | clean | Data & analytics | 2,622 installs | today | |
| analyticscoreyhaines31/marketingskills | clean | Data & analytics | 51,931 installs | today | |
| build-dashboardanthropics/knowledge-work-plugins | clean | Data & analytics | 7,721 installs | today | |
| sql-queriesanthropics/knowledge-work-plugins | clean | Data & analytics | 3,782 installs | today | |
| payment-assistantccxt/ccxt | clean | Data & analytics | 44k stars | today | |
| create-vizanthropics/knowledge-work-plugins | clean | Data & analytics | 4,685 installs | today |
Put this measurement in your README
A badge carrying how many listings this index holds from the repository and how many pass every static structural check. It reads from this index every time somebody loads your page, so it changes when the measurement changes and there is nothing to keep up to date. Free, no account, and the value is not something you or we can set by hand.
[](https://skillworks.kynth.studio/?q=brianmcgillion%2Fre-benchmark)Would rather not hotlink us? Every badge is also served in shields.io’s endpoint schema, so shields renders the image and your readers never talk to our domain:
Published by Toolproof, the masthead over this index and eight others. The method behind the number is at toolproof.kynth.studio/methodology, and the whole thing is readable as JSON with no key at /api.
