Lab description
This lab contains 2 Azure resource(s), 2 assignment(s), and 1 enabled attack path(s).
Source: /home/runner/work/BadZure/BadZure/docs/labs/concepts/key-vault-to-app.yml
This lab contains 2 Azure resource(s), 2 assignment(s), and 1 enabled attack path(s).
The organization contains 1 user(s), 0 group(s), 1 service principal(s), and 0 administrative unit(s).
| Object | Properties |
|---|---|
| sam |
display name: Sam mail nickname: sam user principal name: sam |
None
| Object | Properties |
|---|---|
| mail-reader-app | display name: mail-reader-app |
None
| Type | Source | Target | Properties |
|---|---|---|---|
| ASSIGNED_AZURE_ROLE | sam | kv-app-secrets |
key: vault_secret_to_mailbox__a1 origin: attack_path role: Key Vault Contributor scope type: resource scope ref: kv-app-secrets |
| GRANTED_API_PERMISSION | mail-reader-app | Microsoft Graph |
key: vault_secret_to_mailbox__a2 origin: attack_path permission: Mail.Read permission id: 810c84a8-4a9e-49e6-bf7d-12d183f40d01 api type: graph |
| Object | Properties |
|---|---|
| rg-prod |
location: East US name: rg-prod |
| Object | Properties |
|---|---|
| kv-app-secrets |
location: East US name: kv-app-secrets sku name: standard resource group name: rg-prod |
None
None
None
None
None
None
None
A user reads an app's client secret from a Key Vault and authenticates as that app, which can read every mailbox in the tenant.
controlled app 'mail-reader-app' holds a mail read permission.
MITRE: T1078.004, T1555.006.
High-level Entra identity inventory with user, application service-principal, and managed-identity summaries, group structure, and administrative-unit membership counts.
Subscription and resource-group placement with visible inventory totals, resources grouped by type, and missing placement called out explicitly.
Generated assignment families, roles and permissions, summarized by principal type. Select an aggregate for counts and underlying references.
Legitimate configuration relationships that make this path possible.
Ordered attacker actions from initial access to the path objective.