Lab description
This lab contains 11 Azure resource(s), 18 assignment(s), and 4 enabled attack path(s).
Source: /home/runner/work/BadZure/BadZure/docs/labs/initial-access.yml
This lab contains 11 Azure resource(s), 18 assignment(s), and 4 enabled attack path(s).
The organization contains 6 user(s), 2 group(s), 6 service principal(s), and 0 administrative unit(s).
| Object | Properties |
|---|---|
| ernie.oge |
display name: Ernie Oge mail nickname: ernie.oge user principal name: ernie.oge |
| bobbi.redinger |
display name: Bobbi Redinger mail nickname: bobbi.redinger user principal name: bobbi.redinger |
| lenard.sigley |
display name: Lenard Sigley mail nickname: lenard.sigley user principal name: lenard.sigley |
| curtis.beniquez |
display name: Curtis Beniquez mail nickname: curtis.beniquez user principal name: curtis.beniquez |
| lana.cable |
display name: Lana Cable mail nickname: lana.cable user principal name: lana.cable |
| karyn.stiely |
display name: Karyn Stiely mail nickname: karyn.stiely user principal name: karyn.stiely |
| Object | Properties |
|---|---|
| Cloud Security | display name: Cloud Security |
| Financial Planning | display name: Financial Planning |
| Object | Properties |
|---|---|
| MatrixBoosterSpace | display name: MatrixBoosterSpace |
| ZenithManagerX | display name: ZenithManagerX |
| NanoFlow | display name: NanoFlow |
| NanoEnabler | display name: NanoEnabler |
| NextTrackerPlus | display name: NextTrackerPlus |
| NanoMeshSpark | display name: NanoMeshSpark |
None
| Type | Source | Target | Properties |
|---|---|---|---|
| ASSIGNED_AZURE_ROLE | curtis.beniquez | Infra-Vault-01-5x |
key: credential-emm7c1_src_contrib origin: attack_path role: Virtual Machine Contributor scope type: resource scope ref: Infra-Vault-01-5x |
| ASSIGNED_AZURE_ROLE | Infra-Vault-01-5x | RND-Innov-KVz44p |
key: credential-emm7c1_mi_kv_0 origin: attack_path role: Key Vault Contributor scope type: resource scope ref: RND-Innov-KVz44p |
| ASSIGNED_AZURE_ROLE | Infra-Vault-01-5x | RND-Innov-KVz44p |
key: credential-emm7c1_mi_kv_1 origin: attack_path role: Key Vault Secrets User scope type: resource scope ref: RND-Innov-KVz44p |
| ASSIGNED_AZURE_ROLE | Infra-Vault-01-5x | RND-Innov-KVz44p |
key: credential-emm7c1_mi_kv_2 origin: attack_path role: Key Vault Reader scope type: resource scope ref: RND-Innov-KVz44p |
| ASSIGNED_ENTRA_ROLE | ZenithManagerX | Global Administrator |
key: credential-emm7c1_app_role_0 origin: attack_path role: Global Administrator |
| ASSIGNED_AZURE_ROLE | Fin-Txn-01-pi | RND-Innov-KVz44p |
key: exposed_rdp-uyf34j_mi_kv_0 origin: attack_path role: Key Vault Contributor scope type: resource scope ref: RND-Innov-KVz44p |
| ASSIGNED_AZURE_ROLE | Fin-Txn-01-pi | RND-Innov-KVz44p |
key: exposed_rdp-uyf34j_mi_kv_1 origin: attack_path role: Key Vault Secrets User scope type: resource scope ref: RND-Innov-KVz44p |
| ASSIGNED_AZURE_ROLE | Fin-Txn-01-pi | RND-Innov-KVz44p |
key: exposed_rdp-uyf34j_mi_kv_2 origin: attack_path role: Key Vault Reader scope type: resource scope ref: RND-Innov-KVz44p |
| ASSIGNED_ENTRA_ROLE | NextTrackerPlus | Global Administrator |
key: exposed_rdp-uyf34j_app_role_0 origin: attack_path role: Global Administrator |
| ASSIGNED_AZURE_ROLE | Hr-App-02-gs | CloudSec-Infra-Vaultrrkr |
key: exposed_ssh-pds513_mi_kv_0 origin: attack_path role: Key Vault Contributor scope type: resource scope ref: CloudSec-Infra-Vaultrrkr |
| ASSIGNED_AZURE_ROLE | Hr-App-02-gs | CloudSec-Infra-Vaultrrkr |
key: exposed_ssh-pds513_mi_kv_1 origin: attack_path role: Key Vault Secrets User scope type: resource scope ref: CloudSec-Infra-Vaultrrkr |
| ASSIGNED_AZURE_ROLE | Hr-App-02-gs | CloudSec-Infra-Vaultrrkr |
key: exposed_ssh-pds513_mi_kv_2 origin: attack_path role: Key Vault Reader scope type: resource scope ref: CloudSec-Infra-Vaultrrkr |
| ASSIGNED_ENTRA_ROLE | NanoFlow | Global Administrator |
key: exposed_ssh-pds513_app_role_0 origin: attack_path role: Global Administrator |
| ASSIGNED_AZURE_ROLE | app-review-portal-090u | CloudSec-Infra-Vaultrrkr |
key: vulnerable_web_app-ca19xo_mi_kv_0 origin: attack_path role: Key Vault Contributor scope type: resource scope ref: CloudSec-Infra-Vaultrrkr |
| ASSIGNED_AZURE_ROLE | app-review-portal-090u | CloudSec-Infra-Vaultrrkr |
key: vulnerable_web_app-ca19xo_mi_kv_1 origin: attack_path role: Key Vault Secrets User scope type: resource scope ref: CloudSec-Infra-Vaultrrkr |
| ASSIGNED_AZURE_ROLE | app-review-portal-090u | CloudSec-Infra-Vaultrrkr |
key: vulnerable_web_app-ca19xo_mi_kv_2 origin: attack_path role: Key Vault Reader scope type: resource scope ref: CloudSec-Infra-Vaultrrkr |
| ASSIGNED_ENTRA_ROLE | MatrixBoosterSpace | Global Administrator |
key: vulnerable_web_app-ca19xo_app_role_0 origin: attack_path role: Global Administrator |
| ASSIGNED_AZURE_ROLE | curtis.beniquez | Subscription |
key: recon_reader_curtis.beniquez origin: attack_path role: Reader scope type: subscription |
| Object | Properties |
|---|---|
| AppServices-Prod-RG |
location: West US 2 name: AppServices-Prod-RG |
| Corporate-IT-RG |
location: West US 2 name: Corporate-IT-RG |
| AccessMgmt-Services-RG |
location: West US 2 name: AccessMgmt-Services-RG |
| Object | Properties |
|---|---|
| RND-Innov-KVz44p |
location: West US 2 name: RND-Innov-KVz44p sku name: standard resource group name: AppServices-Prod-RG |
| Env-SecKeys-KV1kea |
location: West US 2 name: Env-SecKeys-KV1kea sku name: standard resource group name: AppServices-Prod-RG |
| CloudSec-Infra-Vaultrrkr |
location: West US 2 name: CloudSec-Infra-Vaultrrkr sku name: standard resource group name: AppServices-Prod-RG |
| Corp-Mgmt-KVen4s |
location: West US 2 name: Corp-Mgmt-KVen4s sku name: standard resource group name: AccessMgmt-Services-RG |
None
| Object | Properties |
|---|---|
| Infra-Vault-01-5x |
vm size: Standard_D2s_v3 resource group name: Corporate-IT-RG location: West US 2 name: Infra-Vault-01-5x admin username: badzureadmin os type: Linux |
| Hr-App-02-gs |
vm size: Standard_D2s_v3 resource group name: Corporate-IT-RG location: West US 2 name: Hr-App-02-gs admin username: badzureadmin os type: Linux |
| Fin-Txn-01-pi |
vm size: Standard_D2s_v3 resource group name: Corporate-IT-RG location: West US 2 name: Fin-Txn-01-pi admin username: badzureadmin os type: Linux |
None
None
None
| Object | Properties |
|---|---|
| app-review-portal-090u |
location: West US 2 name: app-review-portal-090u os type: linux resource group name: Corporate-IT-RG |
None
Attack path from curtis.beniquez to Compromise ZenithManagerX via looted credential.
'ZenithManagerX' is controlled by the attacker.
MITRE: T1078.004, T1528, T1555.006.
Attack path from Fin-Txn-01-pi to Compromise NextTrackerPlus via looted credential.
'NextTrackerPlus' is controlled by the attacker.
MITRE: T1133, T1110.001, T1555.006.
Attack path from Hr-App-02-gs to Compromise NanoFlow via looted credential.
'NanoFlow' is controlled by the attacker.
MITRE: T1133, T1110.001, T1555.006.
Attack path from app-review-portal-090u to Compromise MatrixBoosterSpace via looted credential.
'MatrixBoosterSpace' is controlled by the attacker.
MITRE: T1190, T1555.006.
High-level Entra identity inventory with user, application service-principal, and managed-identity summaries, group structure, and administrative-unit membership counts.
Subscription and resource-group placement with visible inventory totals, resources grouped by type, and missing placement called out explicitly.
Generated assignment families, roles and permissions, summarized by principal type. Select an aggregate for counts and underlying references.
Legitimate configuration relationships that make this path possible.
Ordered attacker actions from initial access to the path objective.
Legitimate configuration relationships that make this path possible.
Ordered attacker actions from initial access to the path objective.
Legitimate configuration relationships that make this path possible.
Ordered attacker actions from initial access to the path objective.
Legitimate configuration relationships that make this path possible.
Ordered attacker actions from initial access to the path objective.