Skip to content
OPS // KITitspentest.sh

E-ROA

ROADtools

Azure AD/Entra ID exploration framework whose roadrecon component dumps the full directory via the Graph API for offline analysis.

Official siteBack to catalog

OVERVIEW

ROADtools (github.com/dirkjanm/ROADtools, by dirkjanm) is a collection of Azure AD/Entra ID tools for offensive and defensive work, built around a shared library (roadlib) plus two main components: ROADrecon, which dumps and explores the full Entra ID directory, and ROADtools Token eXchange (roadtx), which acquires, refreshes, and manipulates Entra ID tokens for a range of authentication flows.

ROADrecon authenticates once with any supported flow (password, device code, refresh token, or a stolen PRT) and then gathers users, groups, applications, service principals, devices, directory roles, administrative units, and Conditional Access policies into a local SQLite database, which a bundled web GUI and a plugin system (including a BloodHound exporter) can query offline without hitting the tenant again.

USE CASES

Practical use cases

  • 01

    Dumping the full Entra ID directory once, then exploring users, groups, apps, and roles offline via the ROADrecon GUI.

  • 02

    Exporting the gathered directory into BloodHound with the built-in plugin for attack-path analysis.

  • 03

    Reviewing Conditional Access policies and administrative-unit scoping for gaps with the `policies` plugin.

  • 04

    Using roadtx to acquire, refresh, or forge Entra ID tokens (device code, PRT, FOCI) for further testing.

QUICK START

During Entra ID assessments to dump the full directory offline for exploration, or to obtain and manipulate tokens with roadtx.

  1. Install ROADtools with `pip install roadtools` (or from source for the latest features).
  2. Authenticate against the tenant with `roadrecon auth`, using a client-provided credential, device code, or token.
  3. Run `roadrecon gather` to dump the directory into a local SQLite database.
  4. Explore the dump with `roadrecon gui`, or export it to BloodHound with `roadrecon plugin bloodhound`.
roadrecon — bash
roadrecon auth -u user@tenant.onmicrosoft.com -p 'Passw0rd!' && roadrecon gather

BEFORE YOU RUN IT

What to check before running it

A full `roadrecon gather` run reads the entire directory and shows up as Graph API activity in Entra ID sign-in logs — agree with the client on scope and expected volume beforehand.

The gathered SQLite database is a complete offline copy of the tenant directory, including role and Conditional Access relationships — store and delete it under the engagement's data-handling rules once analysis is done.

Some roadtx flows (device code, PRT abuse) mimic legitimate sign-ins closely enough to warrant an explicit agreement with the client's SOC about what to expect during the assessment window.

KEEP EXPLORING

View the whole phase →