mirror of
https://github.com/dafthack/GraphRunner
synced 2026-06-08 13:44:02 +00:00
Updated Potential Attack Path Examples (markdown)
@@ -11,8 +11,6 @@ GraphRunner has a lot of different modules that do specific tasks but combining
|
||||
|
||||
Guest users can be injected into groups too but your current user (Entra ID user in the target tenant) needs to be injected first.
|
||||
|
||||

|
||||
|
||||
### Dynamic Group PrivEsc (Abusing membership rule)
|
||||
|
||||
1. Identify dynamic groups (Get-DynamicGroups) that have rules that can be abused such as a rule that adds a user to a group if their email contains “admin”.
|
||||
|
||||
Reference in New Issue
Block a user