Compute

Azure compute is attacked two ways: run code on a resource to reach the host, and steal the managed identity the resource carries to reach the subscription. A VM, container, or cluster you can write to runs your code through a first-class management operation (run command, an extension, command invoke), and the token minted for its attached identity is usually worth more than the host.

Surfaces#

  • Virtual machines: run command, Custom Script Extension, managed-identity theft, and user data.
  • AKS: admin credentials, command invoke, and node-pool identity.
  • Container Registry: admin credentials, ACR Tasks as a managed identity, and image poisoning.
  • Container Instances: running a container as an attached identity.
  • Scale sets: run command and extensions across every instance.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more