BadZure lab: managed-identity.yml

Source: /home/runner/work/BadZure/BadZure/docs/labs/concepts/managed-identity.yml

Lab description

This lab contains 3 Azure resource(s), 2 assignment(s), and 1 enabled attack path(s).

Organization

The organization contains 1 user(s), 0 group(s), 0 service principal(s), and 0 administrative unit(s).

Identity Plane

1Users
0Groups
0Service principals
0Administrative units
2Assignments
Users (1)
ObjectProperties
sam.rivera display name: Sam Rivera
mail nickname: sam.rivera
user principal name: sam.rivera
Groups (0)

None

Applications (0)

None

Administrative Units (0)

None

Assignments(2)
TypeSourceTargetProperties
ASSIGNED_AZURE_ROLE sam.rivera vm-jobs key: vm_identity_to_cosmos__a1
origin: attack_path
role: Virtual Machine Contributor
scope type: resource
scope ref: vm-jobs
ASSIGNED_AZURE_ROLE vm-jobs cosmos-customers key: vm_identity_to_cosmos__a2
origin: attack_path
role: 00000000-0000-0000-0000-000000000002
scope type: resource
scope ref: cosmos-customers
data plane: cosmos_sql

Cloud Plane

1Resource groups
2Azure resources
1Regions
1Attack paths
Resource Groups (1)
ObjectProperties
rg-ops location: East US
name: rg-ops
Key Vaults (0)

None

Storage Accounts (0)

None

Virtual Machines (1)
ObjectProperties
vm-jobs vm size: Standard_D2s_v3
resource group name: rg-ops
location: East US
name: vm-jobs
admin username: badzureadmin
os type: Linux
Logic Apps (0)

None

Automation Accounts (0)

None

Function Apps (0)

None

App Services (0)

None

Cosmos Dbs (1)
ObjectProperties
cosmos-customers database name: cosmos-customers-db
resource group name: rg-ops
location: East US
offer type: Standard
name: cosmos-customers
kind: GlobalDocumentDB
container name: cosmos-customers-container
partition key path: /id

Attack paths

Sensitive Cosmos DB access via a VM's managed identity

reached

An operator with Contributor on a virtual machine controls its managed identity, which can read a sensitive Cosmos DB database.

a controlled principal can read 'cosmos-customers'.

MITRE: T1078.004, T1528.

Ordered narrative (3 steps)
  1. Compromise sam.rivera
  2. Control resource (gain its managed identity) → vm-jobs
  3. Achieve objective: Sensitive Cosmos DB access via a VM's managed identity

Identity / Organization

High-level Entra identity inventory with user, application service-principal, and managed-identity summaries, group structure, and administrative-unit membership counts.

AdministrativeUnitCatalog IdentityCategory IdentitySummary Organization SecurityPrincipalCatalog HAS ADMINISTRATIVE UNITS HAS IDENTITY CATEGORY HAS PRINCIPAL CATALOG SUMMARIZES

Azure Resources

Subscription and resource-group placement with visible inventory totals, resources grouped by type, and missing placement called out explicitly.

CosmosDBSummary ResourceGroup Subscription VirtualMachineSummary CONTAINS

Assignments

Generated assignment families, roles and permissions, summarized by principal type. Select an aggregate for counts and underlying references.

AssignmentCatalog AssignmentFamily PrincipalSummary Role ASSIGNED TO CONTAINS FAMILY CONTAINS KIND

Posture: vm_identity_to_cosmos

Legitimate configuration relationships that make this path possible.

CosmosDB ManagedIdentity Objective User VirtualMachine HAS AZURE ROLE RUNS AS SATISFIES OBJECTIVE

Attack: vm_identity_to_cosmos

Ordered attacker actions from initial access to the path objective.

Attacker ComputeResource DataResource Identity Objective ACHIEVES COMPROMISES EXECUTES ON READS USES MANAGED IDENTITY