BadZure lab: app-ownership.yml

Source: /home/runner/work/BadZure/BadZure/docs/labs/concepts/app-ownership.yml

Lab description

This lab contains 0 Azure resource(s), 2 assignment(s), and 1 enabled attack path(s).

Organization

The organization contains 1 user(s), 0 group(s), 1 service principal(s), and 0 administrative unit(s).

Identity Plane

1Users
0Groups
1Service principals
0Administrative units
2Assignments
Users (1)
ObjectProperties
jordan display name: Jordan
mail nickname: jordan
user principal name: jordan
Groups (0)

None

Applications (1)
ObjectProperties
automation-app display name: automation-app
Administrative Units (0)

None

Assignments(2)
TypeSourceTargetProperties
OWNS_APPLICATION jordan automation-app key: owns_privileged_app__a1
origin: attack_path
ASSIGNED_ENTRA_ROLE automation-app Global Administrator key: owns_privileged_app__a2
origin: attack_path
role: Global Administrator

Cloud Plane

0Resource groups
0Azure resources
0Regions
1Attack paths
Resource Groups (0)

None

Key Vaults (0)

None

Storage Accounts (0)

None

Virtual Machines (0)

None

Logic Apps (0)

None

Automation Accounts (0)

None

Function Apps (0)

None

App Services (0)

None

Cosmos Dbs (0)

None

Attack paths

Global Administrator via owned application

reached

A user owns an application that holds Global Administrator.

controlled principal 'automation-app' holds the target Entra role.

MITRE: T1078.004, T1098.001.

Ordered narrative (3 steps)
  1. Compromise jordan
  2. Take over application via ownership → automation-app
  3. Achieve objective: Global Administrator

Identity / Organization

High-level Entra identity inventory with user, application service-principal, and managed-identity summaries, group structure, and administrative-unit membership counts.

AdministrativeUnitCatalog IdentityCategory IdentitySummary Organization SecurityPrincipalCatalog HAS ADMINISTRATIVE UNITS HAS IDENTITY CATEGORY HAS PRINCIPAL CATALOG SUMMARIZES

Azure Resources

Subscription and resource-group placement with visible inventory totals, resources grouped by type, and missing placement called out explicitly.

Subscription

Assignments

Generated assignment families, roles and permissions, summarized by principal type. Select an aggregate for counts and underlying references.

AssignmentCatalog AssignmentFamily PrincipalSummary Relationship Role ASSIGNED TO CONTAINS FAMILY CONTAINS KIND

Posture: owns_privileged_app

Legitimate configuration relationships that make this path possible.

Credential EntraRole Objective ServicePrincipal User HAS CREDENTIAL HAS ENTRA ROLE OWNS SATISFIES OBJECTIVE

Attack: owns_privileged_app

Ordered attacker actions from initial access to the path objective.

Attacker Credential Identity Objective ACHIEVES ADDS APP CREDENTIAL AUTHENTICATES AS COMPROMISES