Azure compute is attacked two ways: run code on a resource to reach the host, and steal the managed identity the resource carries to reach the subscription. A VM, container, or cluster you can write to runs your code through a first-class management operation (run command, an extension, command invoke), and the token minted for its attached identity is usually worth more than the host.
Surfaces#
- Virtual machines: run command, Custom Script Extension, managed-identity theft, and user data.
- AKS: admin credentials,
command invoke, and node-pool identity. - Container Registry: admin credentials, ACR Tasks as a managed identity, and image poisoning.
- Container Instances: running a container as an attached identity.
- Scale sets: run command and extensions across every instance.