OneDrive to Enum Them All
ID: a9c7df8c-c99c-5ad3-a49a-0365191bbf07
STIX ID: report--a9c7df8c-c99c-5ad3-a49a-0365191bbf07
Feed Name: TrustedSec blog
Threat Score
This blog post details a method for silent, unauthenticated user enumeration via OneDrive personal site URLs and introduces an updated onedrive_enum.py tool that automates tenant lookup, username generation, and logging; it explains how OneDrive URL formats reveal User Principal Names, describes tenant discovery methods, provides wordlist generation guidance, and offers mitigation advice (disabling OneDrive personal sites and changing username formats).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
