Every ARM and data-plane call needs a token or key, so harvesting them is how access widens. Azure credentials arrive as managed-identity tokens minted from the instance metadata service, user and service-principal access and refresh tokens, storage account keys that unlock a whole account's data plane, and the secrets that services like Key Vault, Automation Accounts, and App Service hand back when read.
What folds in here#
- Instance metadata: minting a resource's managed-identity token from IMDS, directly or through SSRF.
- Key Vault: secrets, keys, and certificates over the vault data plane.
- Storage keys:
listKeysto full data-plane access over an account. - Access tokens: cached
azand MSAL tokens looted from disk. - Automation assets: Automation Account credential, variable, and connection assets.
- App settings and connection strings: Function and Web App config secrets.
The IMDS pages are the Azure end of the web server-side request forgery technique, cross-referenced rather than duplicated.