ROADtools / Scripting User-Agent In Entra ID Or Graph Activity
Detects sign-in or Microsoft Graph API activity using user-agent strings characteristic of ROADtools and similar Python-based identity-attack tooling. The rule generalizes beyond ROADtools to catch AzureHound, MicroBurst, MFASweep, GraphRunner, and similar identity attack frameworks by looking for scripting user-agents (python, requests, urllib, curl) which signal non-browser, non-app authentication that is inherently suspicious for Entra ID admin operations.
Microsoft Sentinel (KQL)

