threat-intel Paved With Intent: ROADtools and Nation-State Tactics in the Cloud This report details the use of ROADtools, an open-source toolkit primarily designed for red-teaming and research, by nation-state threat actors in cloud intrusions. The tool leverages legitimate Microsoft APIs to enumerate Entra ID resources, acquire and manipulate tokens, and evade detection, allowing attackers to est… Palo Alto Unit 42 · May 22, 2026 High USentraidazureadtoken management