Azure Files exposes SMB (and NFS) shares backed by a storage account, mounted by servers and workstations for home directories, application data, and backups. Access is by the storage account key (which authenticates straight to the share) or by identity-based auth (Entra Kerberos or on-prem AD DS) mapped to RBAC. A recovered account key is the fastest path: it mounts any share on the account.
Listing and reading shares#
# enumerate shares and files with the account key
az storage share list --account-name acme --account-key <KEY>
az storage file download --account-name acme --account-key <KEY> \
--share-name profiles --path 'user/secrets.config' --dest ./secrets.config
Mounting over SMB#
# mount the share directly with the account key as the password
mount -t cifs //acme.file.core.windows.net/profiles /mnt/share \
-o vers=3.0,username=acme,password=<KEY>,dir_mode=0777,file_mode=0777
Exploitation notes#
- The account key doubles as the SMB password, so
listkeyson the storage account is full share access without any file-share-specific permission. - Azure Files is reachable over the internet on port 445 when the account has no network restriction, so a key plus an open account is remote data access with no foothold in the VNet.
- Look for mounted shares referenced in VM
fstab, scripts, and scheduled tasks to find which shares hold the valuable data.
Tools#
- az CLI (
storage share,storage file): list and pull files. - cifs-utils (
mount -t cifs): mount the share with the key. - MicroBurst: recovers the account keys that unlock the shares.