Files
oscp/Necronomicon/Cloud/Azure/Owner Permissions/Attacking On-Prem to Escalate in Azure.md
2025-11-21 17:17:42 +01:00

482 B

  • With Contributor or Owner role on a subscription, VMs can be used (and possibly created) to begin attacking connected on-prem networks
  • Bloodhound has updates that can also identify/graph Azure roles and relationships
  • Azure tokens are stored on user workstations in the .Azure profile folders - compromise dev machines and pivot
  • With elevated domain rights, might be able to add a new MFA token for a Global Administrator and crack their password to take over their account