Module 10 Links and Resources AAD FEDERATED BACKDOOR Writeup from @DrAzureAd: https://aadinternals.com/post/aadbackdoor/ Install Azure AD module: https://learn.microsoft.com/en-us/powershell/azure/active-directory/install-msonlinev1?view=azureadps-1.0#install-the-azure-ad-module Generate Free CNAME www.myo365.site _________________ MALICIOUS MFA TAKEOVER MSOnline MFA Status: https://github.com/ruudmens/LazyAdmin/blob/master/Office365/MFAStatus.ps1 Temporary Access Passes: https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-temporary-access-pass _________________ SERVICE PRINCIPAL ABUSE Conditional Access Policies: https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/workload-identity Microsoft Graph PowerShell https://learn.microsoft.com/en-us/powershell/microsoftgraph/get-started?view=graph-powershell-1.0 _________________ AUTOMATION ACCOUNT ABUSE NETSPI Owner Persist Runbook: https://github.com/NetSPI/MicroBurst/blob/master/Misc/AutomationRunbook-OwnerPersist.ps1 _________________ STORAGE ACCOUNTS Introduction to Blobs: https://docs.microsoft.com/en-us/azure/storage/blobs/storage-blobs-introduction Interact with the storage account’s containers and blobs: https://.blob.core.windows.net To interact with containers / blob objects the structure is: https://.blob.core.windows.net/container_name/file_name __________________ MALICIOUS DEVICE JOIN @DrAzureAD Writeup: https://aadinternals.com/post/devices/ POST Request: enterpriseregistration.windows.net/EnrollmentServer/device/?api-version=1.0 Malicious Device Join in the Wild (MSFT): https://www.microsoft.com/en-us/security/blog/2022/01/26/evolved-phishing-device-registration-trick-adds-to-phishers-toolbox-for-victims-without-mfa/