Azure Pentest
Last updated
Was this helpful?
Last updated
Was this helpful?
MicroBurst, Lava, Koboko, PowerZure, Stormspotter, and BloodHound
Ffuf
Nabu
Amass
Gbounty bounty automation
Ddosify
Nuclei
Dradis framework report writing
Corsy cors security
4:26 / 7:44
Burp Suite Bambdas
Cloud Security
Azure Security assessment phases
Azure components
azure ad
azure
Attack Scenarios:
- MFA bypass : token dumping : processexp64 dumps: teams : grep for jwt
- evilnginx
Inforamtion Gathering
Tenant ID
Tenant name
Authentication Type
is federation in place
domain
azure services used by target organization
email ids in use
Enum
is azure manangin security or not ( is client on azure or not)
FInding the tenant ID
Recon
cloud pentest
Cloud security audit
prowler
scoutsuite
Azure Storage:
Container
fileshare
tables
queue
References:
Videos
From <>
Azure service finder :
Email enumeration :
cloudsploit