Главная
Study mode:
on
1
Intro
2
Overview
3
Initial Entry Points
4
Permissions Model
5
No Azure Access
6
Reader Rights
7
Escalation Example
8
Contributor Access
9
Local System
10
Storage Accounts
11
Virtual Disks
12
Runbooks
13
Subscriptions
14
Tenant Admin
15
Adding Accounts
16
Adding Guest Accounts
17
Creating Your Own Subscription
18
Automation Accounts
19
Demo
20
Watchers
21
Backdoors
22
Questions
Description:
Explore Azure privilege escalation techniques in this 46-minute conference talk from Derbycon 2019. Learn about initial entry points, the Azure permissions model, and various escalation methods, including reader rights, contributor access, and tenant admin privileges. Discover how to leverage storage accounts, virtual disks, runbooks, and automation accounts for privilege escalation. Gain insights into creating backdoors, adding accounts, and managing subscriptions in Azure environments. Conclude with a live demonstration and a Q&A session to deepen your understanding of Azure security challenges.

Adventures in Azure Privilege Escalation

Add to list