Hi everyone,
Working with Microsoft Entra ID (Azure AD) sign-in logs to hunt down distributed password sprays or track MFA gaps can be a nightmare. There are great SaaS tools out there, but I was always uncomfortable granting third-party cloud services read-access to my entire company's directory and audit logs.
So over the last few months, I built IDSignal — an open-source, zero-cloud dependency security analyzer. It runs entirely locally on your own machine (or via Docker in your private network). Your tenant data never leaves your environment.
What it does automatically:
- Hunts Password Sprays: Unmasks distributed attacks (Event 50126) and groups them by threat actor IPs.
- Spots MFA Gaps: Pinpoints users who do not have MFA configured or active on their accounts.
- Calculates Risk Scores: Combines active threats + missing security controls to give each user an explainable priority score.
- Interactive Dashboard: A really fast, local UI to filter through the noise instantly.
Quick Start (Docker)
I’ve made it incredibly easy to spin up. If you have Docker, it's just one command:
docker run -d --name idsignal -v idsignal_data:/app/data -p 4317:4317 ghcr.io/sertacanbey/idsignal:latest
I’d love for the community to tear it apart, test it, and give me some brutally honest feedback.
GitHub Repo:
https://github.com/SertaCanbey/IDSignal
Live Demo:
https://idsignal.org
Let me know what you think!

Top comments (0)