Lab description
This lab contains 2 Azure resource(s), 2 assignment(s), and 1 enabled attack path(s).
Source: /home/runner/work/BadZure/BadZure/docs/labs/intro.yml
This lab contains 2 Azure resource(s), 2 assignment(s), and 1 enabled attack path(s).
The organization contains 1 user(s), 0 group(s), 1 service principal(s), and 0 administrative unit(s).
| Object | Properties |
|---|---|
| dave.park |
display name: Dave Park mail nickname: dave.park user principal name: dave.park |
None
| Object | Properties |
|---|---|
| hr-sync | display name: hr-sync |
None
| Type | Source | Target | Properties |
|---|---|---|---|
| ASSIGNED_AZURE_ROLE | dave.park | kv-corp-01 |
key: keyvault_to_ga__a1 origin: attack_path role: Key Vault Contributor scope type: resource scope ref: kv-corp-01 |
| ASSIGNED_ENTRA_ROLE | hr-sync | Global Administrator |
key: keyvault_to_ga__a2 origin: attack_path role: Global Administrator |
| Object | Properties |
|---|---|
| rg-corp |
location: East US name: rg-corp |
| Object | Properties |
|---|---|
| kv-corp-01 |
location: East US name: kv-corp-01 sku name: standard resource group name: rg-corp |
None
None
None
None
None
None
None
A developer with Key Vault access reads a privileged application's secret and authenticates as it, reaching Global Administrator.
controlled principal 'hr-sync' holds the target Entra role.
MITRE: T1078.004, T1555.006.
High-level Entra identity inventory with user, application service-principal, and managed-identity summaries, group structure, and administrative-unit membership counts.
Subscription and resource-group placement with visible inventory totals, resources grouped by type, and missing placement called out explicitly.
Generated assignment families, roles and permissions, summarized by principal type. Select an aggregate for counts and underlying references.
Legitimate configuration relationships that make this path possible.
Ordered attacker actions from initial access to the path objective.