Lab description
This lab contains 3 Azure resource(s), 2 assignment(s), and 1 enabled attack path(s).
Source: /home/runner/work/BadZure/BadZure/docs/labs/concepts/managed-identity.yml
This lab contains 3 Azure resource(s), 2 assignment(s), and 1 enabled attack path(s).
The organization contains 1 user(s), 0 group(s), 0 service principal(s), and 0 administrative unit(s).
| Object | Properties |
|---|---|
| sam.rivera |
display name: Sam Rivera mail nickname: sam.rivera user principal name: sam.rivera |
None
None
None
| Type | Source | Target | Properties |
|---|---|---|---|
| ASSIGNED_AZURE_ROLE | sam.rivera | vm-jobs |
key: vm_identity_to_cosmos__a1 origin: attack_path role: Virtual Machine Contributor scope type: resource scope ref: vm-jobs |
| ASSIGNED_AZURE_ROLE | vm-jobs | cosmos-customers |
key: vm_identity_to_cosmos__a2 origin: attack_path role: 00000000-0000-0000-0000-000000000002 scope type: resource scope ref: cosmos-customers data plane: cosmos_sql |
| Object | Properties |
|---|---|
| rg-ops |
location: East US name: rg-ops |
None
None
| Object | Properties |
|---|---|
| vm-jobs |
vm size: Standard_D2s_v3 resource group name: rg-ops location: East US name: vm-jobs admin username: badzureadmin os type: Linux |
None
None
None
None
| Object | Properties |
|---|---|
| cosmos-customers |
database name: cosmos-customers-db resource group name: rg-ops location: East US offer type: Standard name: cosmos-customers kind: GlobalDocumentDB container name: cosmos-customers-container partition key path: /id |
An operator with Contributor on a virtual machine controls its managed identity, which can read a sensitive Cosmos DB database.
a controlled principal can read 'cosmos-customers'.
MITRE: T1078.004, T1528.
High-level Entra identity inventory with user, application service-principal, and managed-identity summaries, group structure, and administrative-unit membership counts.
Subscription and resource-group placement with visible inventory totals, resources grouped by type, and missing placement called out explicitly.
Generated assignment families, roles and permissions, summarized by principal type. Select an aggregate for counts and underlying references.
Legitimate configuration relationships that make this path possible.
Ordered attacker actions from initial access to the path objective.