{"id":13589497,"url":"https://github.com/Kyuu-Ji/Awesome-Azure-Pentest","last_synced_at":"2025-04-08T09:33:02.568Z","repository":{"id":37457099,"uuid":"311740837","full_name":"Kyuu-Ji/Awesome-Azure-Pentest","owner":"Kyuu-Ji","description":"A collection of resources, tools and more for penetration testing and securing Microsofts cloud platform Azure.","archived":false,"fork":false,"pushed_at":"2023-12-27T23:28:31.000Z","size":25,"stargazers_count":946,"open_issues_count":2,"forks_count":175,"subscribers_count":15,"default_branch":"main","last_synced_at":"2024-05-20T00:00:47.380Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Kyuu-Ji.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null}},"created_at":"2020-11-10T17:51:36.000Z","updated_at":"2024-05-12T14:29:59.000Z","dependencies_parsed_at":"2024-01-15T09:05:58.071Z","dependency_job_id":"c1a6ef93-9f4e-4362-9ac3-35cf6b55d47a","html_url":"https://github.com/Kyuu-Ji/Awesome-Azure-Pentest","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Kyuu-Ji%2FAwesome-Azure-Pentest","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Kyuu-Ji%2FAwesome-Azure-Pentest/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Kyuu-Ji%2FAwesome-Azure-Pentest/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Kyuu-Ji%2FAwesome-Azure-Pentest/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Kyuu-Ji","download_url":"https://codeload.github.com/Kyuu-Ji/Awesome-Azure-Pentest/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":222851199,"owners_count":17047298,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T16:00:30.881Z","updated_at":"2024-11-06T09:31:05.351Z","avatar_url":"https://github.com/Kyuu-Ji.png","language":null,"funding_links":[],"categories":["others","Cloud Pentesting","***Cybersecurity Resources***","Other Lists","0x01 资料 :books:","Cloud, Container \u0026 Kubernetes"],"sub_categories":["Azure","***Rootkits (Development)***","TeX Lists","8 云服务文章"],"readme":"# Awesome Azure Penetration Testing\n\nA curated list of useful tools and resources for penetration testing and securing Microsofts cloud platform **Azure**.\n\n## Table of Contents\n\n- [Tools](#tools)\n  - [Enumeration](#enumeration)\n  - [Information Gathering](#information-gathering)\n  - [Lateral Movement](#lateral-movement)\n  - [Exploitation](#exploitation)\n    - [Credential Attacks](#credential-attacks)\n- [Resources](#resources)\n  - [Articles](#articles)\n    - [Lists and Cheat Sheets](#lists-and-cheat-sheets)\n  - [Lab Exercises](#lab-exercises)\n  - [Talks \u0026 Videos](#talks-and-videos)\n  - [Books](#books)\n  - [Tips and Tricks](#tips-and-tricks)\n\n## Tools\n\n### Enumeration\n\n- [o365creeper](https://github.com/LMGsec/o365creeper) - Enumerate valid email addresses\n- [CloudBrute](https://github.com/0xsha/CloudBrute) - Tool to find a cloud infrastructure of a company on top Cloud providers\n- [cloud_enum](https://github.com/initstring/cloud_enum) - Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud\n- [Azucar](https://github.com/nccgroup/azucar) - Security auditing tool for Azure environments\n- [CrowdStrike Reporting Tool for Azure (CRT)](https://github.com/CrowdStrike/CRT) - Query Azure AD/O365 tenants for hard to find permissions and configuration settings\n- [ScoutSuite](https://github.com/nccgroup/ScoutSuite) - Multi-cloud security auditing tool. Security posture assessment of different cloud environments.\n- [BlobHunter](https://github.com/cyberark/blobhunter) - A tool for scanning Azure blob storage accounts for publicly opened blobs\n- [Grayhat Warfare](https://buckets.grayhatwarfare.com/) - Open Azure blobs and AWS bucket search\n- [Office 365 User Enumeration](https://github.com/gremwell/o365enum) - Enumerate valid usernames from Office 365 using ActiveSync, Autodiscover v1 or office.com login page\n- [CloudFox](https://github.com/BishopFox/cloudfox) - Automating situational awareness for cloud penetration tests\n- [Monkey365](https://github.com/silverhack/monkey365) - Conduct Microsoft 365, Azure subscriptions and Azure Active Directory security configuration reviews\n- [Azure-AccessPermissions](https://github.com/csandker/Azure-AccessPermissions) - PowerShell script to enumerate access permissions in an Azure AD environment\n- [Prowler](https://github.com/prowler-cloud/prowler) - Perform AWS and Azure security best practices assessments, audits, incident response, continuous monitoring, hardening and forensics readiness\n\n### Information Gathering\n\n- [o365recon](https://github.com/nyxgeek/o365recon) - Information gathering with valid credentials to Azure\n- [Get-MsolRolesAndMembers.ps1](https://gist.github.com/ciphertxt/2036e614edf4bf920796059017fbbc3d) - Retrieve list of roles and associated role members\n- [ROADtools](https://github.com/dirkjanm/ROADtools) - Framework to interact with Azure AD\n- [PowerZure](https://github.com/hausec/PowerZure) - PowerShell framework to assess Azure security\n- [Azurite](https://github.com/FSecureLABS/Azurite) - Enumeration and reconnaissance activities in the Microsoft Azure Cloud\n- [Sparrow.ps1](https://github.com/cisagov/Sparrow) - Helps to detect possible compromised accounts and applications in the Azure/M365 environment\n- [Hawk](https://github.com/T0pCyber/hawk) - Powershell based tool for gathering information related to O365 intrusions and potential breaches\n- [Microsoft Azure AD Assessment](https://github.com/AzureAD/AzureADAssessment) - Tooling for assessing an Azure AD tenant state and configuration\n- [Cloud Katana](https://github.com/Azure/Cloud-Katana) - Unlocking Serverless Computing to Assess Security Controls\n- [SCuBA M365 Security Baseline Assessment Tool](https://github.com/cisagov/ScubaGear) - Automation to assess the state of your M365 tenant against CISA's baselines\n\n### Lateral Movement\n\n- [Stormspotter](https://github.com/Azure/Stormspotter) - Azure Red Team tool for graphing Azure and Azure Active Directory objects\n- [AzureADLateralMovement](https://github.com/talmaor/AzureADLateralMovement) - Lateral Movement graph for Azure Active Directory\n- [SkyArk](https://github.com/cyberark/SkyArk) - Discover, assess and secure the most privileged entities in Azure and AWS\n- [omigood (OM I GOOD?)](https://github.com/marcosimioni/omigood) - Scanner to detect VMs vulnerable to one of the \"OMIGOD\" vulnerabilities\n\n### Exploitation\n\n- [MicroBurst](https://github.com/NetSPI/MicroBurst) - A collection of scripts for assessing Microsoft Azure security\n- [azuread_decrypt_msol_v2.ps1](https://gist.github.com/xpn/f12b145dba16c2eebdd1c6829267b90c) - Decrypt Azure AD MSOL service account\n- [Microsoft-Teams-GIFShell](https://github.com/bobbyrsec/Microsoft-Teams-GIFShell) - Microsoft Teams can be leveraged by an attacker, to execute a reverse shell between an attacker and victim piped through malicious GIFs sent in Teams messages\n\n#### Credential Attacks\n\n- [MSOLSpray](https://github.com/dafthack/MSOLSpray) - A password spraying tool for Microsoft Online accounts (Azure/O365)\n- [MSOLSpray.py](https://github.com/MartinIngesen/MSOLSpray) - A Python version of the MSOLSpray password spraying tool for Microsoft Online accounts (Azure/O365)\n- [o365spray](https://github.com/0xZDH/o365spray) - Username enumeration and password spraying tool aimed at Microsoft O365\n- [MFASweep](https://github.com/dafthack/MFASweep) -  A tool for checking if MFA is enabled on multiple Microsoft Services Resources\n- [adconnectdump](https://github.com/fox-it/adconnectdump) - Dump Azure AD Connect credentials for Azure AD and Active Directory\n\n## Resources\n\n### Articles\n\n- [Abusing Azure AD SSO with the Primary Refresh Token ](https://dirkjanm.io/abusing-azure-ad-sso-with-the-primary-refresh-token/)\n- [Abusing dynamic groups in Azure AD for Privilege Escalation](https://www.mnemonic.no/blog/abusing-dynamic-groups-in-azure/)\n- [Attacking Azure, Azure AD, and Introducing PowerZure](https://hausec.com/2020/01/31/attacking-azure-azure-ad-and-introducing-powerzure/)\n- [Attacking Azure \u0026 Azure AD, Part II](https://posts.specterops.io/attacking-azure-azure-ad-part-ii-5f336f36697d)\n- [Azure AD Connect for Red Teamers](https://blog.xpnsec.com/azuread-connect-for-redteam/)\n- [Azure AD Introduction for Red Teamers](https://www.synacktiv.com/posts/pentest/azure-ad-introduction-for-red-teamers.html)\n- [Azure AD Pass The Certificate](https://medium.com/@mor2464/azure-ad-pass-the-certificate-d0c5de624597)\n- [Azure AD privilege escalation - Taking over default application permissions as Application Admin](https://dirkjanm.io/azure-ad-privilege-escalation-application-admin/)\n- [Defense and Detection for Attacks Within Azure](https://posts.specterops.io/detecting-attacks-within-azure-bdc40f8c0766)\n- [Hunting Azure Admins for Vertical Escalation](https://www.lares.com/blog/hunting-azure-admins-for-vertical-escalation/)\n- [Impersonating Office 365 Users With Mimikatz](https://www.dsinternals.com/en/impersonating-office-365-users-mimikatz/)\n- [Lateral Movement from Azure to On-Prem AD](https://posts.specterops.io/death-from-above-lateral-movement-from-azure-to-on-prem-ad-d18cb3959d4d)\n- [Malicious Azure AD Application Registrations](https://www.lares.com/blog/malicious-azure-ad-application-registrations/)\n- [Moving laterally between Azure AD joined machines](https://medium.com/@talthemaor/moving-laterally-between-azure-ad-joined-machines-ed1f8871da56)\n- [CrowdStrike Launches Free Tool to Identify and Help Mitigate Risks in Azure Active Directory](https://www.crowdstrike.com/blog/crowdstrike-launches-free-tool-to-identify-and-help-mitigate-risks-in-azure-active-directory/)\n- [Privilege Escalation Vulnerability in Azure Functions](https://www.intezer.com/blog/cloud-security/royal-flush-privilege-escalation-vulnerability-in-azure-functions/)\n- [Azure Application Proxy C2](https://www.trustedsec.com/blog/azure-application-proxy-c2/)\n- [Recovering Plaintext Passwords from Azure Virtual Machines like It’s the 1990s](https://www.guardicore.com/labs/recovering-plaintext-passwords-azure/)\n- [Forensicating Azure VMs](https://isc.sans.edu/forums/diary/Forensicating+Azure+VMs/27136/)\n- [Network Forensics on Azure VMs](https://isc.sans.edu/forums/diary/Network+Forensics+on+Azure+VMs+Part+1/27536/)\n- [Cross-Account Container Takeover in Azure Container Instances](https://unit42.paloaltonetworks.com/azure-container-instances/)\n- [Azure Active Directory password brute-forcing flaw](https://arstechnica.com/information-technology/2021/09/new-azure-active-directory-password-brute-forcing-flaw-has-no-fix/)\n- [How to Detect Azure Active Directory Backdoors: Identity Federation](https://www.inversecos.com/2021/11/how-to-detect-azure-active-directory.html)\n- [Azure App Service vulnerability exposed hundreds of source code repositories](https://blog.wiz.io/azure-app-service-source-code-leak/)\n- [AutoWarp: Cross-Account Vulnerability in Microsoft Azure Automation Service](https://orca.security/resources/blog/autowarp-microsoft-azure-automation-service-vulnerability/)\n- [Microsoft Azure Synapse Pwnalytics](https://medium.com/tenable-techblog/microsoft-azure-synapse-pwnalytics-87c99c036291)\n- [Microsoft Azure Site Recovery DLL Hijacking](https://medium.com/tenable-techblog/microsoft-azure-site-recovery-dll-hijacking-cd8cc34ef80c)\n- [FabriXss (CVE-2022-35829): Abusing a Custom Role User Using CSTI and Stored XSS in Azure Fabric Explorer](https://orca.security/resources/blog/fabrixss-vulnerability-azure-fabric-explorer/)\n- [Untangling Azure Active Directory Principals \u0026 Access Permissions](https://csandker.io/2022/10/19/Untangling-Azure-Permissions.html)\n- [How to Detect OAuth Access Token Theft in Azure](https://www.inversecos.com/2022/08/how-to-detect-oauth-access-token-theft.html)\n- [How to deal with Ransomware on Azure](https://sysdig.com/blog/ransomware-azure-mitigations/)\n- [How Orca found Server-Side Request Forgery (SSRF) Vulnerabilities in four different Azure Services](https://orca.security/resources/blog/ssrf-vulnerabilities-in-four-azure-services/)\n- [EmojiDeploy: Smile! Your Azure web service just got RCE’d](https://ermetic.com/blog/azure/emojideploy-smile-your-azure-web-service-just-got-rced)\n- [Bounce the Ticket and Silver Iodide on Azure AD Kerberos](https://www.silverfort.com/resources/white-paper/bounce-the-ticket-and-silver-iodide-on-azure-ad-kerberos/)\n\n#### Lists and Cheat Sheets\n\n- [List of all Microsoft Portals](https://msportals.io/)\n- [Azure Articles from NetSPI](https://blog.netspi.com/?s=azure)\n- [Azure Cheat Sheet on CloudSecDocs](https://cloudsecdocs.com/azure/services/overview/)\n- [Resources about Azure from Cloudberry Engineering](https://cloudberry.engineering/tags/azure/)\n- [Resources from PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Cloud%20-%20Azure%20Pentest.md)\n- [Encyclopedia on Hacking the Cloud](https://hackingthe.cloud/)\n- [Azure AD - Attack and Defense Playbook](https://github.com/Cloud-Architekt/AzureAD-Attack-Defense)\n- [Azure Security Resources and Notes](https://github.com/rootsecdev/Azure-Red-Team)\n- [Azure Threat Research Matrix](https://microsoft.github.io/Azure-Threat-Research-Matrix/)\n\n### Lab Exercises\n\n- [azure-security-lab](https://github.com/azurecitadel/azure-security-lab) - Securing Azure Infrastructure - Hands on Lab Guide\n- [AzureSecurityLabs](https://github.com/davisanc/AzureSecurityLabs) - Hands-on Security Labs focused on Azure IaaS Security\n- [Building Free Active Directory Lab in Azure](https://medium.com/@kamran.bilgrami/ethical-hacking-lessons-building-free-active-directory-lab-in-azure-6c67a7eddd7f)\n- [Aria Cloud Penetration Testing Tools Container](https://github.com/iknowjason/AriaCloud) - A Docker container for remote penetration testing\n- [PurpleCloud](https://github.com/iknowjason/PurpleCloud) - Multi-use Hybrid + Identity Cyber Range implementing a small Active Directory Domain in Azure alongside Azure AD and Azure Domain Services\n- [BlueCloud](https://github.com/iknowjason/BlueCloud) - Cyber Range system with a Windows VM for security testing with Azure and AWS Terraform support\n- [Azure Red Team Attack and Detect Workshop](https://github.com/mandiant/Azure_Workshop)\n- [SANS Workshop – Building an Azure Pentest Lab for Red Teams](https://www.sans.org/webcasts/sans-workshop-building-azure-pentest-lab-red-teams/) - The link in the description contains a password-protected OVA file that can be used until 2nd March 2024\n\n### Talks and Videos\n\n- [Attacking and Defending the Microsoft Cloud (Office 365 \u0026 Azure AD](https://www.youtube.com/watch?v=SG2ibjuzRJM)\n  - [Presentation Slides](https://i.blackhat.com/USA-19/Wednesday/us-19-Metcalf-Attacking-And-Defending-The-Microsoft-Cloud.pdf)\n- [TR19: I'm in your cloud, reading everyone's emails - hacking Azure AD via Active Directory](https://www.youtube.com/watch?v=JEIR5oGCwdg)\n  - [Presentation Slides](https://troopers.de/downloads/troopers19/TROOPERS19_AD_Im_in_your_cloud.pdf)\n- [Dirk Jan Mollema - Im In Your Cloud Pwning Your Azure Environment - DEF CON 27 Conference](https://www.youtube.com/watch?v=xei8lAPitX8)\n  - [Presentation Slides](https://media.defcon.org/DEF%20CON%2027/DEF%20CON%2027%20presentations/DEFCON-27-Dirk-jan-Mollema-Im-in-your-cloud-pwning-your-azure-environment.pdf)\n- [Adventures in Azure Privilege Escalation Karl Fosaaen](https://www.youtube.com/watch?v=EYtw-XPml0w)\n  - [Presentation Slides](https://notpayloads.blob.core.windows.net/slides/Azure-PrivEsc-DerbyCon9.pdf)\n- [Introducing ROADtools - Azure AD exploration for Red Teams and Blue Teams](https://www.youtube.com/watch?v=o5QDt30Pw_o)\n\n### Books\n\n- [Pentesting Azure Applications](https://nostarch.com/azure)\n\n### Tips and Tricks\n\n- Replace COMPANYNAME with the company name of your choice to check if they use Azure. If the **NameSpaceType** indicates _\"Managed\"_, then the company is using Azure AD:\n```\nhttps://login.microsoftonline.com/getuserrealm.srf?login=username@COMPANYNAME.onmicrosoft.com\u0026xml=1\n```\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FKyuu-Ji%2FAwesome-Azure-Pentest","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FKyuu-Ji%2FAwesome-Azure-Pentest","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FKyuu-Ji%2FAwesome-Azure-Pentest/lists"}