Skip to main content

Azure Penetration Testing

50 hours 8 Modules 20+ Labs Intermediate to Advanced

Course Description

Microsoft Azure has unique attack surfaces. Learn Azure AD attacks, RBAC exploitation, and cloud-to-on-prem pivoting.


Learning Objectives

  1. Enumerate Azure AD and subscriptions
  2. Exploit RBAC misconfigurations
  3. Attack Azure AD Connect
  4. Compromise managed identities
  5. Pivot to on-premises
  6. Evade Azure Sentinel

Course Structure


Modules

Module 1: Azure Fundamentals (5h)

  • Azure architecture
  • Azure AD concepts
  • RBAC overview
  • Subscription model

Module 2: Reconnaissance (6h)

  • Azure enumeration
  • Tenant discovery
  • User enumeration
  • Service principal enum

Module 3: Azure AD Attacks (10h)

  • Password spraying
  • Token theft
  • Consent phishing
  • App registration abuse
  • PRT attacks

Module 4: RBAC Exploitation (7h)

  • Role enumeration
  • Privilege escalation
  • Custom role abuse
  • Resource group attacks

Module 5: Storage Attacks (5h)

  • Blob enumeration
  • SAS token abuse
  • Storage account keys
  • Data exfiltration

Module 6: Compute Attacks (6h)

  • VM metadata attacks
  • Managed identity abuse
  • Function exploitation
  • Container attacks

Module 7: Hybrid Attacks (6h)

  • Azure AD Connect attacks
  • Pass-the-PRT
  • Seamless SSO abuse
  • On-prem to cloud pivot

Module 8: Persistence (5h)

  • Service principal backdoors
  • App registration persistence
  • Conditional access bypass
  • Federation attacks

Tools

ToolPurpose
AzureHoundAD enumeration
ROADtoolsAzure AD toolkit
MicroBurstAzure tools
AADInternalsAzure AD attacks
ScoutSuiteCloud auditing