BadZure lab: chained-showcase.yml

Source: /home/runner/work/BadZure/BadZure/docs/labs/chained-showcase.yml

Lab description

This lab contains 7 Azure resource(s), 20 assignment(s), and 1 enabled attack path(s).

Organization

The organization contains 5 user(s), 5 group(s), 5 service principal(s), and 1 administrative unit(s).

Identity Plane

5Users
5Groups
5Service principals
1Administrative units
20Assignments
Users (5)
ObjectProperties
alice.chen display name: Alice Chen
mail nickname: alice.chen
user principal name: alice.chen
bob.singh display name: Bob Singh
mail nickname: bob.singh
user principal name: bob.singh
carol.diaz display name: Carol Diaz
mail nickname: carol.diaz
user principal name: carol.diaz
dave.kim display name: Dave Kim
mail nickname: dave.kim
user principal name: dave.kim
eve.martin display name: Eve Martin
mail nickname: eve.martin
user principal name: eve.martin
Groups (5)
ObjectProperties
Engineering display name: Engineering
Sales display name: Sales
Finance display name: Finance
IT-Admins display name: IT-Admins
platform-eng display name: platform-eng
Applications (5)
ObjectProperties
cicd-pipeline display name: cicd-pipeline
backup-service display name: backup-service
deploy-agent display name: deploy-agent
release-bot display name: release-bot
directory-sync display name: directory-sync
Administrative Units (1)
ObjectProperties
Finance-Unit display name: Finance-Unit
Assignments(20)
TypeSourceTargetProperties
MEMBER_OF alice.chen Engineering key: baseline__a0
origin: random
MEMBER_OF bob.singh Engineering key: baseline__a1
origin: random
MEMBER_OF carol.diaz Sales key: baseline__a2
origin: random
MEMBER_OF dave.kim Finance key: baseline__a3
origin: random
MEMBER_OF eve.martin IT-Admins key: baseline__a4
origin: random
ASSIGNED_ENTRA_ROLE eve.martin Helpdesk Administrator key: baseline__a5
origin: random
role: Helpdesk Administrator
ASSIGNED_AZURE_ROLE cicd-pipeline rg-dev key: baseline__a6
origin: random
role: Contributor
scope type: resource_group
scope ref: rg-dev
ASSIGNED_AZURE_ROLE IT-Admins rg-prod key: baseline__a7
origin: random
role: Reader
scope type: resource_group
scope ref: rg-prod
ASSIGNED_AZURE_ROLE backup-service stnorthwindprod12 key: baseline__a8
origin: random
role: Storage Blob Data Reader
scope type: resource
scope ref: stnorthwindprod12
GRANTED_API_PERMISSION cicd-pipeline Microsoft Graph key: baseline__a9
origin: random
permission: User.Read.All
permission id: df021288-bdef-4463-88db-98f22de89214
api type: graph
MEMBER_OF_AU dave.kim Finance-Unit key: baseline__a10
origin: random
MEMBER_OF_AU Finance Finance-Unit key: baseline__a11
origin: random
OWNS_GROUP eve.martin IT-Admins key: baseline__a12
origin: random
OWNS_APPLICATION eve.martin cicd-pipeline key: baseline__a13
origin: random
OWNS_APPLICATION alice.chen backup-service key: baseline__a14
origin: random
OWNS_APPLICATION deploy-agent release-bot key: pipeline_to_ga__own1
origin: attack_path
MEMBER_OF release-bot platform-eng key: pipeline_to_ga__mem1
origin: attack_path
ASSIGNED_AZURE_ROLE platform-eng vm-build01 key: pipeline_to_ga__rbac1
origin: attack_path
role: Virtual Machine Contributor
scope type: resource
scope ref: vm-build01
ASSIGNED_AZURE_ROLE vm-build01 kv-pipeline-secrets key: pipeline_to_ga__rbac2
origin: attack_path
role: Key Vault Secrets User
scope type: resource
scope ref: kv-pipeline-secrets
ASSIGNED_ENTRA_ROLE directory-sync Global Administrator key: pipeline_to_ga__role1
origin: attack_path
role: Global Administrator

Cloud Plane

3Resource groups
4Azure resources
1Regions
1Attack paths
Resource Groups (3)
ObjectProperties
rg-prod location: East US
name: rg-prod
rg-dev location: East US
name: rg-dev
rg-compute location: East US
name: rg-compute
Key Vaults (2)
ObjectProperties
kv-northwind-prod location: East US
name: kv-northwind-prod
sku name: standard
resource group name: rg-prod
kv-pipeline-secrets location: East US
name: kv-pipeline-secrets
sku name: standard
resource group name: rg-compute
Storage Accounts (1)
ObjectProperties
stnorthwindprod12 resource group name: rg-prod
location: East US
name: stnorthwindprod12
account tier: Standard
account replication type: LRS
Virtual Machines (1)
ObjectProperties
vm-build01 vm size: Standard_D2s_v3
resource group name: rg-compute
location: East US
name: vm-build01
admin username: badzureadmin
os type: Linux
Logic Apps (0)

None

Automation Accounts (0)

None

Function Apps (0)

None

App Services (0)

None

Cosmos Dbs (0)

None

Attack paths

Global Administrator via CI/CD pipeline

reached

A leaked deployment service-principal secret escalates through application ownership, group membership, a virtual-machine managed identity, and a Key Vault secret theft, all the way to Global Administrator.

controlled principal 'directory-sync' holds the target Entra role.

MITRE: T1078.004, T1098.001, T1098.003, T1528, T1555.006.

Ordered narrative (6 steps)
  1. Compromise deploy-agent
  2. Take over application via ownership → release-bot
  3. Inherit access via group membership → platform-eng
  4. Control resource (gain its managed identity) → vm-build01
  5. Loot planted credential → directory-sync
  6. Achieve objective: Global Administrator

Identity / Organization

High-level Entra identity inventory with user, application service-principal, and managed-identity summaries, group structure, and administrative-unit membership counts.

AdministrativeUnit AdministrativeUnitCatalog Group IdentityCategory IdentitySummary Organization SecurityPrincipalCatalog CONTAINS IDENTITY HAS ADMINISTRATIVE UNITS HAS IDENTITY CATEGORY HAS PRINCIPAL CATALOG SUMMARIZES

Azure Resources

Subscription and resource-group placement with visible inventory totals, resources grouped by type, and missing placement called out explicitly.

KeyVaultSummary ResourceGroup StorageAccountSummary Subscription VirtualMachineSummary CONTAINS

Assignments

Generated assignment families, roles and permissions, summarized by principal type. Select an aggregate for counts and underlying references.

AssignmentCatalog AssignmentFamily Permission PrincipalSummary Relationship Role ASSIGNED TO CONTAINS FAMILY CONTAINS KIND

Posture: pipeline_to_ga

Legitimate configuration relationships that make this path possible.

Credential EntraRole Group KeyVault ManagedIdentity Objective ServicePrincipal VirtualMachine CREDENTIAL FOR HAS AZURE ROLE HAS CREDENTIAL HAS ENTRA ROLE MEMBER OF OWNS RUNS AS SATISFIES OBJECTIVE STORES

Attack: pipeline_to_ga

Ordered attacker actions from initial access to the path objective.

Attacker ComputeResource Credential DataResource Identity Objective ACHIEVES ADDS APP CREDENTIAL AUTHENTICATES AS COMPROMISES EXECUTES ON INHERITS ACCESS READS STEALS CREDENTIAL USES MANAGED IDENTITY