BadZure lab: initial-access.yml

Source: /home/runner/work/BadZure/BadZure/docs/labs/initial-access.yml

Lab description

This lab contains 11 Azure resource(s), 18 assignment(s), and 4 enabled attack path(s).

Organization

The organization contains 6 user(s), 2 group(s), 6 service principal(s), and 0 administrative unit(s).

Identity Plane

6Users
2Groups
6Service principals
0Administrative units
18Assignments
Users (6)
ObjectProperties
ernie.oge display name: Ernie Oge
mail nickname: ernie.oge
user principal name: ernie.oge
bobbi.redinger display name: Bobbi Redinger
mail nickname: bobbi.redinger
user principal name: bobbi.redinger
lenard.sigley display name: Lenard Sigley
mail nickname: lenard.sigley
user principal name: lenard.sigley
curtis.beniquez display name: Curtis Beniquez
mail nickname: curtis.beniquez
user principal name: curtis.beniquez
lana.cable display name: Lana Cable
mail nickname: lana.cable
user principal name: lana.cable
karyn.stiely display name: Karyn Stiely
mail nickname: karyn.stiely
user principal name: karyn.stiely
Groups (2)
ObjectProperties
Cloud Security display name: Cloud Security
Financial Planning display name: Financial Planning
Applications (6)
ObjectProperties
MatrixBoosterSpace display name: MatrixBoosterSpace
ZenithManagerX display name: ZenithManagerX
NanoFlow display name: NanoFlow
NanoEnabler display name: NanoEnabler
NextTrackerPlus display name: NextTrackerPlus
NanoMeshSpark display name: NanoMeshSpark
Administrative Units (0)

None

Assignments(18)
TypeSourceTargetProperties
ASSIGNED_AZURE_ROLE curtis.beniquez Infra-Vault-01-5x key: credential-emm7c1_src_contrib
origin: attack_path
role: Virtual Machine Contributor
scope type: resource
scope ref: Infra-Vault-01-5x
ASSIGNED_AZURE_ROLE Infra-Vault-01-5x RND-Innov-KVz44p key: credential-emm7c1_mi_kv_0
origin: attack_path
role: Key Vault Contributor
scope type: resource
scope ref: RND-Innov-KVz44p
ASSIGNED_AZURE_ROLE Infra-Vault-01-5x RND-Innov-KVz44p key: credential-emm7c1_mi_kv_1
origin: attack_path
role: Key Vault Secrets User
scope type: resource
scope ref: RND-Innov-KVz44p
ASSIGNED_AZURE_ROLE Infra-Vault-01-5x RND-Innov-KVz44p key: credential-emm7c1_mi_kv_2
origin: attack_path
role: Key Vault Reader
scope type: resource
scope ref: RND-Innov-KVz44p
ASSIGNED_ENTRA_ROLE ZenithManagerX Global Administrator key: credential-emm7c1_app_role_0
origin: attack_path
role: Global Administrator
ASSIGNED_AZURE_ROLE Fin-Txn-01-pi RND-Innov-KVz44p key: exposed_rdp-uyf34j_mi_kv_0
origin: attack_path
role: Key Vault Contributor
scope type: resource
scope ref: RND-Innov-KVz44p
ASSIGNED_AZURE_ROLE Fin-Txn-01-pi RND-Innov-KVz44p key: exposed_rdp-uyf34j_mi_kv_1
origin: attack_path
role: Key Vault Secrets User
scope type: resource
scope ref: RND-Innov-KVz44p
ASSIGNED_AZURE_ROLE Fin-Txn-01-pi RND-Innov-KVz44p key: exposed_rdp-uyf34j_mi_kv_2
origin: attack_path
role: Key Vault Reader
scope type: resource
scope ref: RND-Innov-KVz44p
ASSIGNED_ENTRA_ROLE NextTrackerPlus Global Administrator key: exposed_rdp-uyf34j_app_role_0
origin: attack_path
role: Global Administrator
ASSIGNED_AZURE_ROLE Hr-App-02-gs CloudSec-Infra-Vaultrrkr key: exposed_ssh-pds513_mi_kv_0
origin: attack_path
role: Key Vault Contributor
scope type: resource
scope ref: CloudSec-Infra-Vaultrrkr
ASSIGNED_AZURE_ROLE Hr-App-02-gs CloudSec-Infra-Vaultrrkr key: exposed_ssh-pds513_mi_kv_1
origin: attack_path
role: Key Vault Secrets User
scope type: resource
scope ref: CloudSec-Infra-Vaultrrkr
ASSIGNED_AZURE_ROLE Hr-App-02-gs CloudSec-Infra-Vaultrrkr key: exposed_ssh-pds513_mi_kv_2
origin: attack_path
role: Key Vault Reader
scope type: resource
scope ref: CloudSec-Infra-Vaultrrkr
ASSIGNED_ENTRA_ROLE NanoFlow Global Administrator key: exposed_ssh-pds513_app_role_0
origin: attack_path
role: Global Administrator
ASSIGNED_AZURE_ROLE app-review-portal-090u CloudSec-Infra-Vaultrrkr key: vulnerable_web_app-ca19xo_mi_kv_0
origin: attack_path
role: Key Vault Contributor
scope type: resource
scope ref: CloudSec-Infra-Vaultrrkr
ASSIGNED_AZURE_ROLE app-review-portal-090u CloudSec-Infra-Vaultrrkr key: vulnerable_web_app-ca19xo_mi_kv_1
origin: attack_path
role: Key Vault Secrets User
scope type: resource
scope ref: CloudSec-Infra-Vaultrrkr
ASSIGNED_AZURE_ROLE app-review-portal-090u CloudSec-Infra-Vaultrrkr key: vulnerable_web_app-ca19xo_mi_kv_2
origin: attack_path
role: Key Vault Reader
scope type: resource
scope ref: CloudSec-Infra-Vaultrrkr
ASSIGNED_ENTRA_ROLE MatrixBoosterSpace Global Administrator key: vulnerable_web_app-ca19xo_app_role_0
origin: attack_path
role: Global Administrator
ASSIGNED_AZURE_ROLE curtis.beniquez Subscription key: recon_reader_curtis.beniquez
origin: attack_path
role: Reader
scope type: subscription

Cloud Plane

3Resource groups
8Azure resources
1Regions
4Attack paths
Resource Groups (3)
ObjectProperties
AppServices-Prod-RG location: West US 2
name: AppServices-Prod-RG
Corporate-IT-RG location: West US 2
name: Corporate-IT-RG
AccessMgmt-Services-RG location: West US 2
name: AccessMgmt-Services-RG
Key Vaults (4)
ObjectProperties
RND-Innov-KVz44p location: West US 2
name: RND-Innov-KVz44p
sku name: standard
resource group name: AppServices-Prod-RG
Env-SecKeys-KV1kea location: West US 2
name: Env-SecKeys-KV1kea
sku name: standard
resource group name: AppServices-Prod-RG
CloudSec-Infra-Vaultrrkr location: West US 2
name: CloudSec-Infra-Vaultrrkr
sku name: standard
resource group name: AppServices-Prod-RG
Corp-Mgmt-KVen4s location: West US 2
name: Corp-Mgmt-KVen4s
sku name: standard
resource group name: AccessMgmt-Services-RG
Storage Accounts (0)

None

Virtual Machines (3)
ObjectProperties
Infra-Vault-01-5x vm size: Standard_D2s_v3
resource group name: Corporate-IT-RG
location: West US 2
name: Infra-Vault-01-5x
admin username: badzureadmin
os type: Linux
Hr-App-02-gs vm size: Standard_D2s_v3
resource group name: Corporate-IT-RG
location: West US 2
name: Hr-App-02-gs
admin username: badzureadmin
os type: Linux
Fin-Txn-01-pi vm size: Standard_D2s_v3
resource group name: Corporate-IT-RG
location: West US 2
name: Fin-Txn-01-pi
admin username: badzureadmin
os type: Linux
Logic Apps (0)

None

Automation Accounts (0)

None

Function Apps (0)

None

App Services (1)
ObjectProperties
app-review-portal-090u location: West US 2
name: app-review-portal-090u
os type: linux
resource group name: Corporate-IT-RG
Cosmos Dbs (0)

None

Attack paths

Compromise ZenithManagerX via looted credential

reached

Attack path from curtis.beniquez to Compromise ZenithManagerX via looted credential.

'ZenithManagerX' is controlled by the attacker.

MITRE: T1078.004, T1528, T1555.006.

Ordered narrative (4 steps)
  1. Compromise curtis.beniquez
  2. Control resource (gain its managed identity) → Infra-Vault-01-5x
  3. Loot planted credential → ZenithManagerX
  4. Achieve objective: Compromise ZenithManagerX via looted credential

Compromise NextTrackerPlus via looted credential

reached

Attack path from Fin-Txn-01-pi to Compromise NextTrackerPlus via looted credential.

'NextTrackerPlus' is controlled by the attacker.

MITRE: T1133, T1110.001, T1555.006.

Ordered narrative (3 steps)
  1. Initial access via exposed_rdp: code execution on Fin-Txn-01-pi
  2. Loot planted credential → NextTrackerPlus
  3. Achieve objective: Compromise NextTrackerPlus via looted credential

Compromise NanoFlow via looted credential

reached

Attack path from Hr-App-02-gs to Compromise NanoFlow via looted credential.

'NanoFlow' is controlled by the attacker.

MITRE: T1133, T1110.001, T1555.006.

Ordered narrative (3 steps)
  1. Initial access via exposed_ssh: code execution on Hr-App-02-gs
  2. Loot planted credential → NanoFlow
  3. Achieve objective: Compromise NanoFlow via looted credential

Compromise MatrixBoosterSpace via looted credential

reached

Attack path from app-review-portal-090u to Compromise MatrixBoosterSpace via looted credential.

'MatrixBoosterSpace' is controlled by the attacker.

MITRE: T1190, T1555.006.

Ordered narrative (3 steps)
  1. Initial access via vulnerable_web_app: code execution on app-review-portal-090u
  2. Loot planted credential → MatrixBoosterSpace
  3. Achieve objective: Compromise MatrixBoosterSpace via looted credential

Identity / Organization

High-level Entra identity inventory with user, application service-principal, and managed-identity summaries, group structure, and administrative-unit membership counts.

AdministrativeUnitCatalog Group IdentityCategory IdentitySummary Organization SecurityPrincipalCatalog CONTAINS IDENTITY HAS ADMINISTRATIVE UNITS HAS IDENTITY CATEGORY HAS PRINCIPAL CATALOG SUMMARIZES

Azure Resources

Subscription and resource-group placement with visible inventory totals, resources grouped by type, and missing placement called out explicitly.

AppServiceSummary KeyVaultSummary ResourceGroup Subscription VirtualMachineSummary CONTAINS

Assignments

Generated assignment families, roles and permissions, summarized by principal type. Select an aggregate for counts and underlying references.

AssignmentCatalog AssignmentFamily PrincipalSummary Role ASSIGNED TO CONTAINS FAMILY CONTAINS KIND

Posture: credential

Legitimate configuration relationships that make this path possible.

Credential KeyVault ManagedIdentity Objective ServicePrincipal User VirtualMachine CREDENTIAL FOR HAS AZURE ROLE HAS CREDENTIAL RUNS AS SATISFIES OBJECTIVE STORES

Attack: credential

Ordered attacker actions from initial access to the path objective.

Attacker ComputeResource Credential DataResource Identity Objective ACHIEVES AUTHENTICATES AS COMPROMISES EXECUTES ON READS STEALS CREDENTIAL USES MANAGED IDENTITY

Posture: exposed_rdp

Legitimate configuration relationships that make this path possible.

Credential KeyVault ManagedIdentity Objective ServicePrincipal VirtualMachine CREDENTIAL FOR HAS AZURE ROLE HAS CREDENTIAL RUNS AS SATISFIES OBJECTIVE STORES

Attack: exposed_rdp

Ordered attacker actions from initial access to the path objective.

Attacker ComputeResource Credential DataResource Identity Objective ACHIEVES AUTHENTICATES AS EXPLOITS READS STEALS CREDENTIAL

Posture: exposed_ssh

Legitimate configuration relationships that make this path possible.

Credential KeyVault ManagedIdentity Objective ServicePrincipal VirtualMachine CREDENTIAL FOR HAS AZURE ROLE HAS CREDENTIAL RUNS AS SATISFIES OBJECTIVE STORES

Attack: exposed_ssh

Ordered attacker actions from initial access to the path objective.

Attacker ComputeResource Credential DataResource Identity Objective ACHIEVES AUTHENTICATES AS EXPLOITS READS STEALS CREDENTIAL

Posture: vulnerable_web_app

Legitimate configuration relationships that make this path possible.

AppService Credential KeyVault ManagedIdentity Objective ServicePrincipal CREDENTIAL FOR HAS AZURE ROLE HAS CREDENTIAL RUNS AS SATISFIES OBJECTIVE STORES

Attack: vulnerable_web_app

Ordered attacker actions from initial access to the path objective.

Attacker ComputeResource Credential DataResource Identity Objective ACHIEVES AUTHENTICATES AS EXPLOITS READS STEALS CREDENTIAL