Storage

Storage is where the data lives, so it is the usual objective once a foothold or a storage key is held. Azure storage breaks into object storage (Blob, exposed through public containers, account keys, and SAS), block storage (managed disk snapshots restored offline), and shared file systems (Azure Files over SMB). Most compromise here is exposure or key theft rather than an exploit: an anonymous container, a leaked SAS URL with a year of validity, a snapshot exported to a disk you control.

What folds in here#

  • Blob storage: finding public containers and reading blobs through account keys, RBAC, or anonymous access.
  • SAS tokens: over-scoped account, service, and user-delegation shared access signatures.
  • Disk snapshots: snapshotting and exporting a managed disk to read a VM's OS disk offline.
  • File shares: Azure Files SMB shares reached through storage keys or identity-based access.

Enumeration folds into each page: finding the account or share is the first half of reaching its data. The account key, where recovered, is the master credential for every data plane below and is covered under credentials.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more