Azure / Entra ID attacks

SkillWeb & browsing

Attack Azure / Entra ID, managed-identity token theft, Entra (Azure AD) role abuse, and app/ storage misconfig. Load when the target is on Azure, you hold Azure creds/a token, or see Entra/AAD/azurewebsites/blob.core.windows.net. Signals: 169.254.169.254 IMDS, Managed Identity, az cli, Entra roles, service principals.

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the Azure / Entra ID attacks skill

What this skill tells your AI

The instructions your AI receives, as published by noorqureshi/sploitagent in skills/cloud/cloud-azure/SKILL.md and read by ahel’s review.

When it applies

Target on Azure and you have some access — SSRF into a VM/App Service with a Managed Identity, a leaked service-principal secret/cert, or a foothold. Goal: steal tokens, abuse Entra roles, reach resources.

Why it works

Azure resources authenticate via Managed Identities and service principals; the IMDS hands out OAuth tokens for them. Entra (Azure AD) roles and app permissions are widely over-assigned, and several (adding credentials to a service principal, role assignment, Owner on a subscription) escalate to control.

Method

  1. Managed Identity → token (via SSRF, or on the host): GET http://169.254.169.254/metadata/identity/ oauth2/token?api-version=2018-02-01&resource=https://management.azure.com/ with header Metadata: true (→ cloud-imds-ssrf). Also request tokens for Graph, Key Vault, Storage.
  2. Authenticate & enumerate: az login with the SP or token; enumerate roles/resources; map Entra with AzureHound (BloodHound for Azure); ScoutSuite/MicroBurst for misconfig.
  3. Entra / IAM privesc: add credentials to a service principal you can manage → auth as it; abusive Entra roles (Application/Cloud App Admin, Privileged Role Admin); role assignment (Microsoft.Authorization/roleAssignments/write) → grant yourself Owner; consent grants.
  4. Resources & secrets: Key Vault (token for vault.azure.net), Storage blobs (→ storage misconfig), Automation Accounts / runbooks (RCE as their identity), App Service.
  5. Prove impact read-only as the escalated principal; avoid persistent role changes.

Gotchas

  • Two planes: ARM (resources) and Microsoft Graph / Entra (identity) — get tokens for the right resource/audience.
  • Managed-identity SSRF needs the Metadata: true header — header-less SSRF won't work (that's the mitigation).
  • AzureHound reveals Entra attack paths you'd miss manually — run it early.

Verify success

Escalated access proven — a token/role letting you act beyond your start (Key Vault secret read, subscription role you granted, resource action as a managed identity).

References

Azure IMDS & Managed Identity docs; AzureHound/BloodHound; MicroBurst; Entra privesc research.

Signals

GitHub stars
20
Forks
7
Last commit
Sep 2026

ahel review

  • S4info
    community integration, published by noorqureshi, not azure

Automated review, not a security audit. Ruleset v1+k2.

Advanced
Item type
skill
Key
cloud-azure-noorqureshi
Source
github.com/noorqureshi/sploitagent