Azure Blob storage holds objects in containers inside a storage account, addressed at https://<account>.blob.core.windows.net/<container>. Access comes three ways, and each is an attack path: anonymous when a container's public access level is set to blob or container, an account key (the master credential for the whole account), or Azure RBAC data roles such as Storage Blob Data Reader. The work is finding the account, finding a container, and reaching its blobs by whichever of the three is open.
What folds in here#
- Enumeration: discovering storage accounts and public containers through naming guesses and anonymous listing.
- Access: reading and writing blobs through account keys, RBAC data roles, or misconfigured anonymous access.