ROADTools

MITRE ATT&CK: S0684 View on attack.mitre.org

Aliases: ROADTools

First seen
2019-07-30 00:00:00
Malware type
spyware
Operating systems
identity-provider
Profile updated
2026-07-07 15:33:21

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services

Context

ROADTools is a framework for enumerating Azure Active Directory environments. The tool is written in Python and publicly available on GitHub.

Detection coverage

  • 67 Sigma rules

Malware & tools used

  • Remote System Discovery (attack-pattern)
  • Automated Collection (attack-pattern)
  • Cloud Service Discovery (attack-pattern)
  • Cloud Account (attack-pattern)
  • Cloud Groups (attack-pattern)
  • Cloud Accounts (attack-pattern)

Used by threat actors

Reports & references

  • MITRE ATT&CK — S0684 (report)
  • github.com — Roadtools (report)

External references