BadZure lab: intro.yml

Source: /home/runner/work/BadZure/BadZure/docs/labs/intro.yml

Lab description

This lab contains 2 Azure resource(s), 2 assignment(s), and 1 enabled attack path(s).

Organization

The organization contains 1 user(s), 0 group(s), 1 service principal(s), and 0 administrative unit(s).

Identity Plane

1Users
0Groups
1Service principals
0Administrative units
2Assignments
Users (1)
ObjectProperties
dave.park display name: Dave Park
mail nickname: dave.park
user principal name: dave.park
Groups (0)

None

Applications (1)
ObjectProperties
hr-sync display name: hr-sync
Administrative Units (0)

None

Assignments(2)
TypeSourceTargetProperties
ASSIGNED_AZURE_ROLE dave.park kv-corp-01 key: keyvault_to_ga__a1
origin: attack_path
role: Key Vault Contributor
scope type: resource
scope ref: kv-corp-01
ASSIGNED_ENTRA_ROLE hr-sync Global Administrator key: keyvault_to_ga__a2
origin: attack_path
role: Global Administrator

Cloud Plane

1Resource groups
1Azure resources
1Regions
1Attack paths
Resource Groups (1)
ObjectProperties
rg-corp location: East US
name: rg-corp
Key Vaults (1)
ObjectProperties
kv-corp-01 location: East US
name: kv-corp-01
sku name: standard
resource group name: rg-corp
Storage Accounts (0)

None

Virtual Machines (0)

None

Logic Apps (0)

None

Automation Accounts (0)

None

Function Apps (0)

None

App Services (0)

None

Cosmos Dbs (0)

None

Attack paths

Global Administrator via Key Vault

reached

A developer with Key Vault access reads a privileged application's secret and authenticates as it, reaching Global Administrator.

controlled principal 'hr-sync' holds the target Entra role.

MITRE: T1078.004, T1555.006.

Ordered narrative (3 steps)
  1. Compromise dave.park
  2. Loot planted credential → hr-sync
  3. Achieve objective: Global Administrator

Identity / Organization

High-level Entra identity inventory with user, application service-principal, and managed-identity summaries, group structure, and administrative-unit membership counts.

AdministrativeUnitCatalog IdentityCategory IdentitySummary Organization SecurityPrincipalCatalog HAS ADMINISTRATIVE UNITS HAS IDENTITY CATEGORY HAS PRINCIPAL CATALOG SUMMARIZES

Azure Resources

Subscription and resource-group placement with visible inventory totals, resources grouped by type, and missing placement called out explicitly.

KeyVaultSummary ResourceGroup Subscription CONTAINS

Assignments

Generated assignment families, roles and permissions, summarized by principal type. Select an aggregate for counts and underlying references.

AssignmentCatalog AssignmentFamily PrincipalSummary Role ASSIGNED TO CONTAINS FAMILY CONTAINS KIND

Posture: keyvault_to_ga

Legitimate configuration relationships that make this path possible.

Credential EntraRole KeyVault Objective ServicePrincipal User CREDENTIAL FOR HAS AZURE ROLE HAS CREDENTIAL HAS ENTRA ROLE SATISFIES OBJECTIVE STORES

Attack: keyvault_to_ga

Ordered attacker actions from initial access to the path objective.

Attacker Credential DataResource Identity Objective ACHIEVES AUTHENTICATES AS COMPROMISES READS STEALS CREDENTIAL