StorageCertificateTheft¶
Category: Resource based
A compromised identity has direct read access to an Azure Storage Account that holds an application's certificate. The attacker downloads the certificate and its private key and uses certificate-based authentication to impersonate the application.
What makes it possible¶
Storage Blob Data Reader and similar roles let the holder download blobs. When a blob is an application's certificate and private key, the attacker can authenticate as the application using certificate-based authentication. As with Key Vault theft, the access is direct.
Configure it¶
attack_paths:
storage_theft:
initial_access:
vector: compromised_credential
principal_type: user
privilege_escalation:
technique: StorageCertificateTheft
assignment_type: direct
objective:
entra_role: 62e90394-69f5-4237-9190-012177145e10 # Global Administrator
Ensure the baseline includes storage_accounts: 1 (or more).
Verify it¶
A reachable verdict confirms a controlled principal can read the storage account and take over the application whose certificate is stored there.
Variants¶
- Assignment:
assignment_typecontrols whether the storage role is held directly or through a group. - Foothold:
principal_type: userorservice_principal.
To reach a Storage Account through a stolen managed-identity token instead, use ManagedIdentityAbuse with target_resource_type: storage_account. Full options are in the Atomic Reference.