> For the complete documentation index, see [llms.txt](https://red.0xbad53c.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://red.0xbad53c.com/red-team-operations/azure-and-o365.md).

# Azure and O365

- [PRT Abuse from Userland with Cobalt Strike](https://red.0xbad53c.com/red-team-operations/azure-and-o365/prt-abuse-from-userland-with-cobalt-strike.md): This page describes how to acquire an Azure AD Single Sign-On session from a non-privileged user session on a Windows machine. The acquired token is later used to enumerate Azure AD via ROADTools.
- [Enumerate Azure AD with AzureHound from Userland](https://red.0xbad53c.com/red-team-operations/azure-and-o365/enumerate-azure-ad-with-azurehound-from-userland.md): This page describes how to enumerate Azure AD with AzureHound, starting from a non-privileged user session on a Windows machine.
