|
1 | 1 | # Admins-Analyzer |
2 | 2 | # |
3 | 3 | # @author: Martin Willing |
4 | | -# @copyright: Copyright (c) 2025 Martin Willing. All rights reserved. Licensed under the MIT license. |
| 4 | +# @copyright: Copyright (c) 2026 Martin Willing. All rights reserved. Licensed under the MIT license. |
5 | 5 | # @contact: Any feedback or suggestions are always welcome and much appreciated - mwilling@lethal-forensics.com |
6 | 6 | # @url: https://lethal-forensics.com/ |
7 | | -# @date: 2025-10-21 |
| 7 | +# @date: 2026-05-01 |
8 | 8 | # |
9 | 9 | # |
10 | 10 | # ██╗ ███████╗████████╗██╗ ██╗ █████╗ ██╗ ███████╗ ██████╗ ██████╗ ███████╗███╗ ██╗███████╗██╗ ██████╗███████╗ |
|
22 | 22 | # |
23 | 23 | # |
24 | 24 | # Tested on Windows 10 Pro (x64) Version 22H2 (10.0.19045.6456) and PowerShell 5.1 (5.1.19041.6456) |
25 | | -# Tested on Windows 10 Pro (x64) Version 22H2 (10.0.19045.6456) and PowerShell 7.5.3 |
| 25 | +# Tested on Windows 10 Pro (x64) Version 22H2 (10.0.19045.6456) and PowerShell 7.6.1 |
26 | 26 | # |
27 | 27 | # |
28 | 28 | ############################################################################################################################################################################################# |
|
35 | 35 | .DESCRIPTION |
36 | 36 | Admins-Analyzer.ps1 is a PowerShell script utilized to simplify the analysis of the Admin Directory Roles extracted via "Microsoft-Extractor-Suite" by Invictus Incident Response. |
37 | 37 |
|
38 | | - https://github.com/invictus-ir/Microsoft-Extractor-Suite (Microsoft-Extractor-Suite v4.0.0) |
| 38 | + https://github.com/invictus-ir/Microsoft-Extractor-Suite (Microsoft-Extractor-Suite v4.0.2) |
39 | 39 |
|
40 | 40 | https://microsoft-365-extractor-suite.readthedocs.io/en/latest/functionality/Azure/GetUserInfo.html#retrieve-all-administrator-directory-roles |
41 | 41 |
|
@@ -244,7 +244,7 @@ Write-Output "" |
244 | 244 |
|
245 | 245 | # Header |
246 | 246 | Write-Output "Admins-Analyzer - Automated Processing of Microsoft Entra Directory Roles for DFIR" |
247 | | -Write-Output "(c) 2025 Martin Willing at Lethal-Forensics (https://lethal-forensics.com/)" |
| 247 | +Write-Output "(c) 2026 Martin Willing at Lethal-Forensics (https://lethal-forensics.com/)" |
248 | 248 | Write-Output "" |
249 | 249 |
|
250 | 250 | # Analysis date (ISO 8601) |
@@ -433,8 +433,8 @@ $Host.UI.RawUI.WindowTitle = "$DefaultWindowsTitle" |
433 | 433 | # SIG # Begin signature block |
434 | 434 | # MIIrywYJKoZIhvcNAQcCoIIrvDCCK7gCAQExCzAJBgUrDgMCGgUAMGkGCisGAQQB |
435 | 435 | # gjcCAQSgWzBZMDQGCisGAQQBgjcCAR4wJgIDAQAABBAfzDtgWUsITrck0sYpfvNR |
436 | | -# AgEAAgEAAgEAAgEAAgEAMCEwCQYFKw4DAhoFAAQUNyZ7UmILUdUC0TFfqm5+cKfn |
437 | | -# 8e+ggiUEMIIFbzCCBFegAwIBAgIQSPyTtGBVlI02p8mKidaUFjANBgkqhkiG9w0B |
| 436 | +# AgEAAgEAAgEAAgEAAgEAMCEwCQYFKw4DAhoFAAQU4XqKkkprBsYfN1a80UVeWLU3 |
| 437 | +# nuCggiUEMIIFbzCCBFegAwIBAgIQSPyTtGBVlI02p8mKidaUFjANBgkqhkiG9w0B |
438 | 438 | # AQwFADB7MQswCQYDVQQGEwJHQjEbMBkGA1UECAwSR3JlYXRlciBNYW5jaGVzdGVy |
439 | 439 | # MRAwDgYDVQQHDAdTYWxmb3JkMRowGAYDVQQKDBFDb21vZG8gQ0EgTGltaXRlZDEh |
440 | 440 | # MB8GA1UEAwwYQUFBIENlcnRpZmljYXRlIFNlcnZpY2VzMB4XDTIxMDUyNTAwMDAw |
@@ -636,33 +636,33 @@ $Host.UI.RawUI.WindowTitle = "$DefaultWindowsTitle" |
636 | 636 | # Z28gUHVibGljIENvZGUgU2lnbmluZyBDQSBSMzYCEQCMQZ6TvyvOrIgGKDt2Gb08 |
637 | 637 | # MAkGBSsOAwIaBQCgeDAYBgorBgEEAYI3AgEMMQowCKACgAChAoAAMBkGCSqGSIb3 |
638 | 638 | # DQEJAzEMBgorBgEEAYI3AgEEMBwGCisGAQQBgjcCAQsxDjAMBgorBgEEAYI3AgEV |
639 | | -# MCMGCSqGSIb3DQEJBDEWBBSqslDmo+/tUIlEr6d8b/8wOFPuPzANBgkqhkiG9w0B |
640 | | -# AQEFAASCAgCkUOS5c7ecWh9JyZwieaCuWGFsX4V33zAaqOWdoQMFaZoJFiT82Gw6 |
641 | | -# Mk671Mt6mubj/898Dc59q1t+OoUkn3F4tHPD1H1iwU5D47SnWASgly76TJmBrNQX |
642 | | -# CdZGtibhp0KxWDBM9kGMufj0HjRdu7QLnpsRGXMkNdsUVTjnSLBzffmMIyUGM9GK |
643 | | -# KAPerWRMQzc7+AGwo3fnlqmIvCDWqhCWox7GjUYDFU+eWtVsUOv5yJ/a+vEr7vvm |
644 | | -# A5JlWaKLFMvO1GVy2+GNKVRhoFNp46Scn8ENroi3XOhl8nYfgEwP1qqSIPu4GtPj |
645 | | -# 4JhCrLOXBRhN60Lv5hNdm8Dh4dBhp+l0dQXJCMuTze5s8KX8b82A+kajtbwG+oEX |
646 | | -# s2tS57l45pKooR1S+hDjb1YKxGtULoBnD2RmLDJztqz3rT3xPxhRXOTvC54KqBpI |
647 | | -# RZX3m/FgL6XkC2kXo0UMg10ju2XeXTA0BLmS53O/VWXmCtsKUJP3w0r/ALyqKIzF |
648 | | -# f4nLBA//O8JS962vVoTYtoV4BkL7FcUmHJujSKbjPwxtK+PQWvaB6lDxk+M3E7iT |
649 | | -# hIbgPudiz4Z8chS3Bb/zMLn9kn0K9FfSlu5o2Zyt1PH/rsS7CKRiJLdEvgM2Tyw1 |
650 | | -# kgEqrEaxU+t68/AM90F/XgrdCz4tgeU0G1kqm2EfrTmA/SpXYLRXrKGCAyMwggMf |
| 639 | +# MCMGCSqGSIb3DQEJBDEWBBQsigOQHXAgVm+V80JxfxxaIWfwKDANBgkqhkiG9w0B |
| 640 | +# AQEFAASCAgAHKMyY02qJ3JS2PvS4UPqlqMAoecZ0Q9aAsTxijEHoRZDZF/3rISat |
| 641 | +# NBUBLhytIp4xBiIKib2piGpYxB/gKWEvT+sZUS2CsyWYbmvWkoOhIjzAyteCK5gQ |
| 642 | +# TOmJHwSc214N1oavTLMCGFiYng7qIR4KrERQt5JB3a0tIvaexaD7wTdzB/839WnX |
| 643 | +# zGN8ecYGs6xNUC1VYDov3KpUggzExzb0yIARgLL+sxmXin9MO0/qMxK1X0g1ULOb |
| 644 | +# S4j4cEE9y+FrYUKIFtKwmI5s1y5v3WQKsMBrUVEb3iMH8RG8WEeBsgszjqdVOqtD |
| 645 | +# B77D20JEvV6FggqBnk5DmYnVtt3zv7ND+i/yBS8XOrRnEHrPCe8VYHLN7vVqkgDg |
| 646 | +# ZNqdDN/2idhcAMtqSzmKAmqmM8bU4MI+91Gg5A52c9vQfvaX4wNz8xbstfjX7Lem |
| 647 | +# KRkRmnSRfr1aLPqmbkc4+ZK7N08rRZw3B08yzSgrxF4/YqD/d2N91lEFkHw31jul |
| 648 | +# 7iEAbH+3lay6mUQRoTymq8eLQXrsnAreYDoIVrMu+76bdhhGwCnjWkol+rFM8MBW |
| 649 | +# mXCXLfMevGNO1Hc3zbXczlPSJyO8nf0L3InU6d/TwnOvbcNBFT1TjwrMpJeYH505 |
| 650 | +# w8fQLyprSx0SUMkT0+E5vXJtm/sKA552lAM6AC573Yk9HW9Tzf0BqKGCAyMwggMf |
651 | 651 | # BgkqhkiG9w0BCQYxggMQMIIDDAIBATBqMFUxCzAJBgNVBAYTAkdCMRgwFgYDVQQK |
652 | 652 | # Ew9TZWN0aWdvIExpbWl0ZWQxLDAqBgNVBAMTI1NlY3RpZ28gUHVibGljIFRpbWUg |
653 | 653 | # U3RhbXBpbmcgQ0EgUjM2AhEApCk7bh7d16c0CIetek63JDANBglghkgBZQMEAgIF |
654 | | -# AKB5MBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTI1 |
655 | | -# MTAyMTA1MzExMVowPwYJKoZIhvcNAQkEMTIEMMy0ConhqXA5mQcEEbW9St/ZDwyd |
656 | | -# ZxXJJ8nSOnBN5ua+ihsu8OvIv7pqWnCyJC5UcDANBgkqhkiG9w0BAQEFAASCAgA3 |
657 | | -# 4PcMAv+pM7cJ1/a2Y9am2cZOblO3s+MjA2zSUaHs/uLO2CAWHHBTrRB8gRCgyw3J |
658 | | -# LKk4+RnbdJvktnA3gzkxyRrnNgdzx99tnm6HBV1xOjloFR1G9w09GNdrm8y7P5kT |
659 | | -# QMZdGq3OxPXjVRniDA8QBj36Ld4+E8ukFQ3qdGQGu78arvN8atOo6wDWaD9PNOOI |
660 | | -# KUg+CvPmNl05XJ/X4hRK2lv/PrJHQxxtw54Oowy738pr69/PD1f9cYO47PvpLIxB |
661 | | -# uVCeTR0rZ8ThpvGwLvBf/kTehoJvwf5GyLzTtxw8D+YX6nLEAXX+v3icJhZqil4T |
662 | | -# sD5V74SsFTWCUzI4sm8J8I34qn6CUN4LvMBzqUJ+gb+qb82AkkT3M8drTkLKvFd2 |
663 | | -# A/wgLjeYRd0xVOkd8RFKH2YYDPIasSTTRDqiW1rofI4u1PfpDnl7Aw4nIafvibED |
664 | | -# 8nMOIKOIoOD9Fi/iQvq1yHfYV+pKtB+84yAp0Y2w5YmUWKiBWqY4QiTh82z8zD/i |
665 | | -# NHqrzHbeSkvKXQNn664Czu6fOUY1omPjKkL/00K0zEXzhzW+CDH2SAGxrifsp07r |
666 | | -# 2lmhFWIOL3DBba3BWVerNGV3iHHFVTniVq48CsyEenqzrpoCykq9SNuyhxm5DuIt |
667 | | -# wJyzahmtthlCrwIP+xyUKcC5TEZI1uSdZkNgGvA4ww== |
| 654 | +# AKB5MBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTI2 |
| 655 | +# MDUwMTEwNDk1NFowPwYJKoZIhvcNAQkEMTIEMDE3wLMd0oMSxRPQ6e8Usg/u5h4g |
| 656 | +# Q5tDj1RStXcC2rtTi7oJJ7A/B3OSWWo5j1mrzzANBgkqhkiG9w0BAQEFAASCAgAp |
| 657 | +# bFmSZWVxCyKzyT9OvDGvvXmFpCad3ksp7ns9KcBkdFs0fhkd2L1VaNicB2PVsOxn |
| 658 | +# 6MEilSfGq9eLsj4iJafXuQp6sVkfmS4+4qdDWxuA9Qv/BKu/CnDtPydy8x68UdBT |
| 659 | +# 9fmt+kKb04fQSyZ5CirQdLjcAh9Vz7y7bb1vpI7tkCehPL8CgIGj3OUuhJ5GtS+t |
| 660 | +# dd8da3e8ZvTq7F7LZYHnYq2LDVFcvq3g+4lwGsEOClop+3PO3Jg2xdNne5wu2zHM |
| 661 | +# 9oZ177Vmf06eFW+O+Itzc6K31Je9gOEXlGKvual+Nn45aDqqABla9aqgso7mpI7/ |
| 662 | +# t4Tyld0MUp1bbNHrpK3LGbYeLk42so/ep1DStg4Czr+xuwkfWOxhubufJT638Cg4 |
| 663 | +# 9CM5C3M9zXDb2ivVz1IfmzwVlEi02+JPzExybUEpIs42/UpEOrbBB8UaXk103enz |
| 664 | +# P9lhEzB3RRxDKAmHxTr1W3nPJUerab6fflJ/um+6coV/+Q0AcmqZ0joO4HAkwy0Q |
| 665 | +# yFdZAn42p6FNytrCUnvHPjZ+tRQ20sKTwf+SKF3VuP+s9RVIDeqX5G6d0oxSyoP1 |
| 666 | +# +wUBjPzTBfPR9tsEOhvpo1I46r9Qdonw5BJdEJLlVjqk6IFhKiaaoMnfqvrmJbXr |
| 667 | +# QsnKOCUwBATv2gEt08qNDAzUkCKP/3qTD5RUy1f2ZQ== |
668 | 668 | # SIG # End signature block |
0 commit comments