The US government has released an open source tool, Untitled Goose Tool, to help security teams identify flaws in Microsoft cloud services. Developed by the U.S. Cybersecurity & Infrastructure Security Agency (CISA) and the U.S. Department of Energy national laboratory, Sandia, the tool harvests telemetry data from Azure Active Directory, Microsoft Azure, and Microsoft 365. It can export and review sign-in and audit logs from Azure, as well as detect malicious activity from Microsoft Defender for Endpoint and Defender for Internet of Things.