Azure Penetration Testing
Course Description
Microsoft Azure has unique attack surfaces. Learn Azure AD attacks, RBAC exploitation, and cloud-to-on-prem pivoting.
Learning Objectives
- Enumerate Azure AD and subscriptions
- Exploit RBAC misconfigurations
- Attack Azure AD Connect
- Compromise managed identities
- Pivot to on-premises
- Evade Azure Sentinel
Course Structure
Modules
Module 1: Azure Fundamentals (5h)
- Azure architecture
- Azure AD concepts
- RBAC overview
- Subscription model
Module 2: Reconnaissance (6h)
- Azure enumeration
- Tenant discovery
- User enumeration
- Service principal enum
Module 3: Azure AD Attacks (10h)
- Password spraying
- Token theft
- Consent phishing
- App registration abuse
- PRT attacks
Module 4: RBAC Exploitation (7h)
- Role enumeration
- Privilege escalation
- Custom role abuse
- Resource group attacks
Module 5: Storage Attacks (5h)
- Blob enumeration
- SAS token abuse
- Storage account keys
- Data exfiltration
Module 6: Compute Attacks (6h)
- VM metadata attacks
- Managed identity abuse
- Function exploitation
- Container attacks
Module 7: Hybrid Attacks (6h)
- Azure AD Connect attacks
- Pass-the-PRT
- Seamless SSO abuse
- On-prem to cloud pivot
Module 8: Persistence (5h)
- Service principal backdoors
- App registration persistence
- Conditional access bypass
- Federation attacks
Tools
| Tool | Purpose |
|---|---|
| AzureHound | AD enumeration |
| ROADtools | Azure AD toolkit |
| MicroBurst | Azure tools |
| AADInternals | Azure AD attacks |
| ScoutSuite | Cloud auditing |
📄️ Overview
Microsoft Azure security testing: Azure AD, RBAC, and cloud service exploitation