Lab description
This lab contains 7 Azure resource(s), 20 assignment(s), and 1 enabled attack path(s).
Source: /home/runner/work/BadZure/BadZure/docs/labs/chained-showcase.yml
This lab contains 7 Azure resource(s), 20 assignment(s), and 1 enabled attack path(s).
The organization contains 5 user(s), 5 group(s), 5 service principal(s), and 1 administrative unit(s).
| Object | Properties |
|---|---|
| alice.chen |
display name: Alice Chen mail nickname: alice.chen user principal name: alice.chen |
| bob.singh |
display name: Bob Singh mail nickname: bob.singh user principal name: bob.singh |
| carol.diaz |
display name: Carol Diaz mail nickname: carol.diaz user principal name: carol.diaz |
| dave.kim |
display name: Dave Kim mail nickname: dave.kim user principal name: dave.kim |
| eve.martin |
display name: Eve Martin mail nickname: eve.martin user principal name: eve.martin |
| Object | Properties |
|---|---|
| Engineering | display name: Engineering |
| Sales | display name: Sales |
| Finance | display name: Finance |
| IT-Admins | display name: IT-Admins |
| platform-eng | display name: platform-eng |
| Object | Properties |
|---|---|
| cicd-pipeline | display name: cicd-pipeline |
| backup-service | display name: backup-service |
| deploy-agent | display name: deploy-agent |
| release-bot | display name: release-bot |
| directory-sync | display name: directory-sync |
| Object | Properties |
|---|---|
| Finance-Unit | display name: Finance-Unit |
| Type | Source | Target | Properties |
|---|---|---|---|
| MEMBER_OF | alice.chen | Engineering |
key: baseline__a0 origin: random |
| MEMBER_OF | bob.singh | Engineering |
key: baseline__a1 origin: random |
| MEMBER_OF | carol.diaz | Sales |
key: baseline__a2 origin: random |
| MEMBER_OF | dave.kim | Finance |
key: baseline__a3 origin: random |
| MEMBER_OF | eve.martin | IT-Admins |
key: baseline__a4 origin: random |
| ASSIGNED_ENTRA_ROLE | eve.martin | Helpdesk Administrator |
key: baseline__a5 origin: random role: Helpdesk Administrator |
| ASSIGNED_AZURE_ROLE | cicd-pipeline | rg-dev |
key: baseline__a6 origin: random role: Contributor scope type: resource_group scope ref: rg-dev |
| ASSIGNED_AZURE_ROLE | IT-Admins | rg-prod |
key: baseline__a7 origin: random role: Reader scope type: resource_group scope ref: rg-prod |
| ASSIGNED_AZURE_ROLE | backup-service | stnorthwindprod12 |
key: baseline__a8 origin: random role: Storage Blob Data Reader scope type: resource scope ref: stnorthwindprod12 |
| GRANTED_API_PERMISSION | cicd-pipeline | Microsoft Graph |
key: baseline__a9 origin: random permission: User.Read.All permission id: df021288-bdef-4463-88db-98f22de89214 api type: graph |
| MEMBER_OF_AU | dave.kim | Finance-Unit |
key: baseline__a10 origin: random |
| MEMBER_OF_AU | Finance | Finance-Unit |
key: baseline__a11 origin: random |
| OWNS_GROUP | eve.martin | IT-Admins |
key: baseline__a12 origin: random |
| OWNS_APPLICATION | eve.martin | cicd-pipeline |
key: baseline__a13 origin: random |
| OWNS_APPLICATION | alice.chen | backup-service |
key: baseline__a14 origin: random |
| OWNS_APPLICATION | deploy-agent | release-bot |
key: pipeline_to_ga__own1 origin: attack_path |
| MEMBER_OF | release-bot | platform-eng |
key: pipeline_to_ga__mem1 origin: attack_path |
| ASSIGNED_AZURE_ROLE | platform-eng | vm-build01 |
key: pipeline_to_ga__rbac1 origin: attack_path role: Virtual Machine Contributor scope type: resource scope ref: vm-build01 |
| ASSIGNED_AZURE_ROLE | vm-build01 | kv-pipeline-secrets |
key: pipeline_to_ga__rbac2 origin: attack_path role: Key Vault Secrets User scope type: resource scope ref: kv-pipeline-secrets |
| ASSIGNED_ENTRA_ROLE | directory-sync | Global Administrator |
key: pipeline_to_ga__role1 origin: attack_path role: Global Administrator |
| Object | Properties |
|---|---|
| rg-prod |
location: East US name: rg-prod |
| rg-dev |
location: East US name: rg-dev |
| rg-compute |
location: East US name: rg-compute |
| Object | Properties |
|---|---|
| kv-northwind-prod |
location: East US name: kv-northwind-prod sku name: standard resource group name: rg-prod |
| kv-pipeline-secrets |
location: East US name: kv-pipeline-secrets sku name: standard resource group name: rg-compute |
| Object | Properties |
|---|---|
| stnorthwindprod12 |
resource group name: rg-prod location: East US name: stnorthwindprod12 account tier: Standard account replication type: LRS |
| Object | Properties |
|---|---|
| vm-build01 |
vm size: Standard_D2s_v3 resource group name: rg-compute location: East US name: vm-build01 admin username: badzureadmin os type: Linux |
None
None
None
None
None
A leaked deployment service-principal secret escalates through application ownership, group membership, a virtual-machine managed identity, and a Key Vault secret theft, all the way to Global Administrator.
controlled principal 'directory-sync' holds the target Entra role.
MITRE: T1078.004, T1098.001, T1098.003, T1528, T1555.006.
High-level Entra identity inventory with user, application service-principal, and managed-identity summaries, group structure, and administrative-unit membership counts.
Subscription and resource-group placement with visible inventory totals, resources grouped by type, and missing placement called out explicitly.
Generated assignment families, roles and permissions, summarized by principal type. Select an aggregate for counts and underlying references.
Legitimate configuration relationships that make this path possible.
Ordered attacker actions from initial access to the path objective.