E-ROA
ROADtools
Azure AD/Entra ID exploration framework whose roadrecon component dumps the full directory via the Graph API for offline analysis.
OVERVIEW
ROADtools (github.com/dirkjanm/ROADtools, by dirkjanm) is a collection of Azure AD/Entra ID tools for offensive and defensive work, built around a shared library (roadlib) plus two main components: ROADrecon, which dumps and explores the full Entra ID directory, and ROADtools Token eXchange (roadtx), which acquires, refreshes, and manipulates Entra ID tokens for a range of authentication flows.
ROADrecon authenticates once with any supported flow (password, device code, refresh token, or a stolen PRT) and then gathers users, groups, applications, service principals, devices, directory roles, administrative units, and Conditional Access policies into a local SQLite database, which a bundled web GUI and a plugin system (including a BloodHound exporter) can query offline without hitting the tenant again.
USE CASES
Practical use cases
- 01
Dumping the full Entra ID directory once, then exploring users, groups, apps, and roles offline via the ROADrecon GUI.
- 02
Exporting the gathered directory into BloodHound with the built-in plugin for attack-path analysis.
- 03
Reviewing Conditional Access policies and administrative-unit scoping for gaps with the `policies` plugin.
- 04
Using roadtx to acquire, refresh, or forge Entra ID tokens (device code, PRT, FOCI) for further testing.
QUICK START
During Entra ID assessments to dump the full directory offline for exploration, or to obtain and manipulate tokens with roadtx.
- Install ROADtools with `pip install roadtools` (or from source for the latest features).
- Authenticate against the tenant with `roadrecon auth`, using a client-provided credential, device code, or token.
- Run `roadrecon gather` to dump the directory into a local SQLite database.
- Explore the dump with `roadrecon gui`, or export it to BloodHound with `roadrecon plugin bloodhound`.
roadrecon auth -u user@tenant.onmicrosoft.com -p 'Passw0rd!' && roadrecon gatherBEFORE YOU RUN IT
What to check before running it
A full `roadrecon gather` run reads the entire directory and shows up as Graph API activity in Entra ID sign-in logs — agree with the client on scope and expected volume beforehand.
The gathered SQLite database is a complete offline copy of the tenant directory, including role and Conditional Access relationships — store and delete it under the engagement's data-handling rules once analysis is done.
Some roadtx flows (device code, PRT abuse) mimic legitimate sign-ins closely enough to warrant an explicit agreement with the client's SOC about what to expect during the assessment window.