Artifacts that may be indicative of UNC2452 and other threat actor activity are detected using a PowerShell module.
Features:
Disclaimer: The intended use for the tool is strictly educational and should not be used for any other purposes.
Download link: https://github.com/mandiant/Mandiant-Azure-AD-Investigator