Networking

Azure network reachability decides what a foothold can touch. Network security groups gate traffic, VNets and peerings define the internal blast radius, private endpoints pull PaaS services onto internal addresses, and the edge services (Front Door, CDN, Bastion) and DNS records are each abusable in their own right. Enumeration here turns the subscription's network posture into a target list and a pivot map.

What folds in here#

  • Network security groups: reading and rewriting NSG rules to expose or reach filtered resources.
  • VNet: peering, service endpoints, and private access to pivot between subnets.
  • Private endpoints: Private Link to reach PaaS resources over internal addresses.
  • DNS takeover: claiming dangling records from deleted App Service, Traffic Manager, CDN, or public-IP resources.
  • Front Door and CDN: origin exposure, host-header and routing abuse, and dangling endpoints.
  • Bastion: pivoting into private VMs over RDP and SSH.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more