daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

cicd-azure-devops.md (1095B)


      1 ---
      2 title: "CI/CD - Azure DevOps"
      3 section: "DevOps"
      4 sectionSlug: "devops"
      5 sourcePath: "docs/devops/cicd-azure-devops.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/devops/cicd-azure-devops.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # CI/CD - Azure DevOps
     12 
     13 ## Azure Pipelines
     14 
     15 The configuration files for azure pipelines are normally located in the root directory of the repository and called - `azure-pipelines.yml`\
     16 You can tell if the pipeline builds pull requests based on its trigger instructions. Look for `pr:` instruction:
     17 
     18 ```yaml
     19 trigger:
     20   branches:
     21       include:
     22       - master
     23       - refs/tags/*
     24 pr:
     25 - master
     26 ```
     27 
     28 ## Secret Extractions
     29 
     30 Extract secrets for these service connection:
     31 
     32 * AzureRM
     33 * GitHub
     34 * AWS
     35 * SonarQube
     36 * SSH
     37 
     38 ```ps1
     39 nord-stream.py devops ... --build-yaml test.yml --build-type ssh  
     40 ```
     41 
     42 ## References
     43 
     44 * [Azure DevOps CICD Pipelines - Command Injection with Parameters, Variables and a discussion on Runner hijacking - Sana Oshika - May 1 2023](https://pulsesecurity.co.nz/advisories/Azure-Devops-Command-Injection)