DEV Community

Cover image for I built an open-source, 100% local Microsoft Entra Security Analyzer
Sertaç Canbey
Sertaç Canbey

Posted on

I built an open-source, 100% local Microsoft Entra Security Analyzer

Hi everyone,

Working with Microsoft Entra ID (Azure AD) sign-in logs to hunt down distributed password sprays or track MFA gaps can be a nightmare. There are great SaaS tools out there, but I was always uncomfortable granting third-party cloud services read-access to my entire company's directory and audit logs.

So over the last few months, I built IDSignal — an open-source, zero-cloud dependency security analyzer. It runs entirely locally on your own machine (or via Docker in your private network). Your tenant data never leaves your environment.

Dashboard Preview

What it does automatically:

  • Hunts Password Sprays: Unmasks distributed attacks (Event 50126) and groups them by threat actor IPs.
  • Spots MFA Gaps: Pinpoints users who do not have MFA configured or active on their accounts.
  • Calculates Risk Scores: Combines active threats + missing security controls to give each user an explainable priority score.
  • Interactive Dashboard: A really fast, local UI to filter through the noise instantly.

Quick Start (Docker)

I’ve made it incredibly easy to spin up. If you have Docker, it's just one command:

docker run -d --name idsignal -v idsignal_data:/app/data -p 4317:4317 ghcr.io/sertacanbey/idsignal:latest
Enter fullscreen mode Exit fullscreen mode

I’d love for the community to tear it apart, test it, and give me some brutally honest feedback.

GitHub Repo:
https://github.com/SertaCanbey/IDSignal
Live Demo:
https://idsignal.org

Let me know what you think!

Top comments (0)