Catégorie : Divers

Storage | Scanning Azure Blob Storage


In this article, I will show you how you can scan an Azure Blob to identity potential public storage containers. By default when you create a new container, you have 3 options to define the public level access:

  • Private: No public access to this container (default configuration).
  • Blob: Public access is permitted to this container and its blobs.
  • Container: Public access is permitted to blobs in this container, but not to the container itself.

To leverage this attack, we will use a function including in the MicroBurst tool.

Invoke-EnumerateAzureBlobs -Base yourcompanyname

In this example, I will use an additional containerlist file with some folders examples (dev, non, prod, devprod, ….)

Invoke-EnumerateAzureBlobs -Base zigmaxlab -Folders .\containerlist.txt


AAD | Abuse Service Principals


Attackers want to target service principals because:

  • Service accounts and service principals do not have MFA
  • Attackers can log into Azure using a service principal account
  • These accounts exist with all applications in Azure (most companies have several) 
  • These accounts could be controlled through conditional access only with an Azure Active Directory P2.

with the service principal using Azure CLI:

az login –service-principal -u YourServicePrincipald -p YourServicePrincipalPassword -tenant YourTenantId –allow-no-subscriptions

To prevent this attack, you can define a Conditional Access policies for your service principals. You need to have an Azure Active Directory Premium P2 to enable this feature.