BadZure lab: key-vault-to-app.yml

Source: /home/runner/work/BadZure/BadZure/docs/labs/concepts/key-vault-to-app.yml

Lab description

This lab contains 2 Azure resource(s), 2 assignment(s), and 1 enabled attack path(s).

Organization

The organization contains 1 user(s), 0 group(s), 1 service principal(s), and 0 administrative unit(s).

Identity Plane

1Users
0Groups
1Service principals
0Administrative units
2Assignments
Users (1)
ObjectProperties
sam display name: Sam
mail nickname: sam
user principal name: sam
Groups (0)

None

Applications (1)
ObjectProperties
mail-reader-app display name: mail-reader-app
Administrative Units (0)

None

Assignments(2)
TypeSourceTargetProperties
ASSIGNED_AZURE_ROLE sam kv-app-secrets key: vault_secret_to_mailbox__a1
origin: attack_path
role: Key Vault Contributor
scope type: resource
scope ref: kv-app-secrets
GRANTED_API_PERMISSION mail-reader-app Microsoft Graph key: vault_secret_to_mailbox__a2
origin: attack_path
permission: Mail.Read
permission id: 810c84a8-4a9e-49e6-bf7d-12d183f40d01
api type: graph

Cloud Plane

1Resource groups
1Azure resources
1Regions
1Attack paths
Resource Groups (1)
ObjectProperties
rg-prod location: East US
name: rg-prod
Key Vaults (1)
ObjectProperties
kv-app-secrets location: East US
name: kv-app-secrets
sku name: standard
resource group name: rg-prod
Storage Accounts (0)

None

Virtual Machines (0)

None

Logic Apps (0)

None

Automation Accounts (0)

None

Function Apps (0)

None

App Services (0)

None

Cosmos Dbs (0)

None

Attack paths

Read all mail via a vaulted app secret

reached

A user reads an app's client secret from a Key Vault and authenticates as that app, which can read every mailbox in the tenant.

controlled app 'mail-reader-app' holds a mail read permission.

MITRE: T1078.004, T1555.006.

Ordered narrative (3 steps)
  1. Compromise sam
  2. Loot planted credential → mail-reader-app
  3. Achieve objective: Read all mail via a vaulted app secret

Identity / Organization

High-level Entra identity inventory with user, application service-principal, and managed-identity summaries, group structure, and administrative-unit membership counts.

AdministrativeUnitCatalog IdentityCategory IdentitySummary Organization SecurityPrincipalCatalog HAS ADMINISTRATIVE UNITS HAS IDENTITY CATEGORY HAS PRINCIPAL CATALOG SUMMARIZES

Azure Resources

Subscription and resource-group placement with visible inventory totals, resources grouped by type, and missing placement called out explicitly.

KeyVaultSummary ResourceGroup Subscription CONTAINS

Assignments

Generated assignment families, roles and permissions, summarized by principal type. Select an aggregate for counts and underlying references.

AssignmentCatalog AssignmentFamily Permission PrincipalSummary Role ASSIGNED TO CONTAINS FAMILY CONTAINS KIND

Posture: vault_secret_to_mailbox

Legitimate configuration relationships that make this path possible.

Credential KeyVault MicrosoftGraph Objective ServicePrincipal User CREDENTIAL FOR HAS API PERMISSION HAS AZURE ROLE HAS CREDENTIAL SATISFIES OBJECTIVE STORES

Attack: vault_secret_to_mailbox

Ordered attacker actions from initial access to the path objective.

Attacker Credential DataResource Identity Objective ACHIEVES AUTHENTICATES AS COMPROMISES READS STEALS CREDENTIAL