Full-scope Azure Red Team assessment targeting enterprise cloud infrastructure. The engagement followed a structured adversarial methodology covering Azure AD enumeration, RBAC privilege escalation paths, managed identity abuse, storage account exposure analysis, Key Vault misconfigurations, and network security group reviews. All findings mapped to the MITRE ATT&CK Cloud matrix.
Structured red team approach following industry-standard cloud adversarial frameworks and the MITRE ATT&CK Cloud matrix.
Reconnaissance of Azure AD tenant configuration, user enumeration via Microsoft Graph API, analysis of conditional access policies, identity federation misconfigurations, and service principal permission auditing. Identified over-privileged applications and unused guest accounts.
Mapped Azure RBAC role assignments across subscriptions and management groups. Identified 3 privilege escalation paths through Contributor roles on automation accounts, Key Vault access policies, and managed identity assignments enabling lateral movement.
Assessed Azure Storage accounts for anonymous public access, soft-delete configurations, and network ACL bypasses. Key Vault firewall settings and access policies evaluated for secret exposure risks. Storage account shared access signature (SAS) token leakage identified.
Selected findings from the assessment report, organized by severity and Azure service category.
Techniques mapped to the MITRE ATT&CK Cloud matrix for structured threat intelligence.
T1526 — Cloud Service Discovery
T1087 — Account Discovery
T1078 — Valid Accounts
T1484 — Domain Policy Modification
T1528 — Steal Application Access Token
T1552 — Unsecured Credentials
T1021 — Remote Services
T1210 — Exploitation of Remote Services
Complete Azure Red Team report covering methodology, reconnaissance, findings, privilege escalation paths, and remediation recommendations.
Full deliverables available in the project repository.