Skip to main content
Red Team Assessment — 2026

Azure Red Team
Cloud Infrastructure Assessment

Full-scope Azure Red Team assessment targeting enterprise cloud infrastructure. The engagement followed a structured adversarial methodology covering Azure AD enumeration, RBAC privilege escalation paths, managed identity abuse, storage account exposure analysis, Key Vault misconfigurations, and network security group reviews. All findings mapped to the MITRE ATT&CK Cloud matrix.

MITRE ATT&CK Azure AD OWASP

Engagement at a Glance

0[1] Findings Identified
0[2] Azure Services Assessed
0[3] MITRE Techniques
0[4] Privilege Escalation Paths

Assessment Methodology

Structured red team approach following industry-standard cloud adversarial frameworks and the MITRE ATT&CK Cloud matrix.

Azure AD Enumeration

Reconnaissance of Azure AD tenant configuration, user enumeration via Microsoft Graph API, analysis of conditional access policies, identity federation misconfigurations, and service principal permission auditing. Identified over-privileged applications and unused guest accounts.

RBAC & Privilege Escalation

Mapped Azure RBAC role assignments across subscriptions and management groups. Identified 3 privilege escalation paths through Contributor roles on automation accounts, Key Vault access policies, and managed identity assignments enabling lateral movement.

Storage & Secrets Exposure

Assessed Azure Storage accounts for anonymous public access, soft-delete configurations, and network ACL bypasses. Key Vault firewall settings and access policies evaluated for secret exposure risks. Storage account shared access signature (SAS) token leakage identified.

Key Security Findings

Selected findings from the assessment report, organized by severity and Azure service category.

CRITICAL Over-privileged Managed Identity with Contributor access across subscription
HIGH Key Vault accessible from all networks — firewall disabled
HIGH Storage account anonymous blob access enabled on production container
MEDIUM Azure AD guest user with Global Reader role not reviewed in 6+ months
MEDIUM SAS token with no expiry date on read-write storage container
LOW NSG rules allowing RDP access from any source on management subnet

MITRE ATT&CK Cloud Mapping

Techniques mapped to the MITRE ATT&CK Cloud matrix for structured threat intelligence.

Discovery

T1526 — Cloud Service Discovery
T1087 — Account Discovery

Privilege Escalation

T1078 — Valid Accounts
T1484 — Domain Policy Modification

Credential Access

T1528 — Steal Application Access Token
T1552 — Unsecured Credentials

Lateral Movement

T1021 — Remote Services
T1210 — Exploitation of Remote Services

Full Assessment Report

Complete Azure Red Team report covering methodology, reconnaissance, findings, privilege escalation paths, and remediation recommendations.

Download Report (PDF) Back to Red Team

References

  1. Test Plan — 12 attack techniques mapped to MITRE ATT&CK with Azure-specific Tactics, Techniques, and Procedures.
  2. Attack Scenarios — 5 adversary scenarios simulating real-world Azure attack paths (phishing-to-cloud, privilege escalation, data exfiltration).
  3. Findings Report — 8 findings with risk ratings, evidence artifacts, and remediation guidance.
  4. Access Paths — 3 initial access vectors tested (phishing, credential stuffing, MFA bypass).

Full deliverables available in the project repository.