Azure

Azure is driven through the Azure Resource Manager (ARM) API, authorized by Azure RBAC role assignments and reached with a user token, a service-principal secret, or a resource's managed identity. Almost every attack is an RBAC question: what scope does my principal hold, which role lets it escalate, and which resource's managed identity can it borrow. The surfaces below follow that shape, with privilege escalation living inside identity and credential theft inside credentials.

This area is the resource and management plane only. Microsoft Entra ID (the tenant directory, formerly Azure AD) is attacked like a directory and lives under Entra ID next to Active Directory; user and application identity attacks (device code, PRT, consent, Entra roles) are there, not here.

Enumeration#

Enumeration folds into each surface, but the subscription-wide inventory is run first: az account list and az resource list for the resource graph, Azure Resource Graph queries for scale, role assignments with az role assignment list --all, and managed identities with ROADtools, Stormspotter, or AzureHound (BARK) for the RBAC and resource graph. Those feed every surface below.

Surfaces#

  • Identity: Azure RBAC role and custom-role writes, elevate-access, managed-identity assignment, and PIM activation.
  • Credentials: managed-identity tokens from IMDS, Key Vault, storage keys, Automation assets, and app settings.
  • Compute: VM run command and extensions, AKS, Container Registry, Container Instances, and scale sets.
  • Storage: blob enumeration and access, SAS tokens, disk snapshots, and file shares.
  • Serverless: Functions, Logic Apps, Automation Accounts, App Service, and Deployment Scripts.
  • Data: SQL Database, Cosmos DB, Data Factory, Synapse, and storage tables.
  • Networking: network security groups and VNet, private endpoints, DNS takeover, Front Door, and Bastion.
  • Logging and detection: tampering with the Activity Log, Azure Monitor, Defender for Cloud, and Sentinel.
  • Messaging: Service Bus, Event Hubs, Event Grid, and Storage Queues.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more