Module 2 Links and Resources Microsoft Azure AD is now Microsoft Entra ID https://www.microsoft.com/en-au/security/business/identity-access/azure-active-directory Microsoft Logging Changes (Effective September 2023) https://www.microsoft.com/en-us/security/blog/2023/07/19/expanding-cloud-logging-to-give-customers-deeper-security-visibility/ Managed Identities https://learn.microsoft.com/en-us/azure/active-directory/managed-identities-azure-resources/managed-identities-status Web Application Portal.azure.com admin.exchange.microsoft.com compliance.microsoft.com security.microsoft.com Graph Explorer / Graph PowerShell SDK https://developer.microsoft.com/en-us/graph/graph-explorer https://learn.microsoft.com/en-us/powershell/microsoftgraph/get-started?view=graph-powershell-1.0 MsOnline https://learn.microsoft.com/en-us/powershell/module/msonline/?view=azureadps-1.0 Azure CLI https://learn.microsoft.com/en-us/cli/azure/install-azure-cli Decode JWT https://jwt.io/ Module 3 Links and Resources Please note that when you are signing up for the 90-day developer program, it's a different account to the Azure trial. You can MOVE the subscription from the trial to your developer account by following the instructions in this blog here: https://vmlabblog.com/2020/02/how-to-move-an-azure-subscription/ M365 Developer Program https://developer.microsoft.com/en-us/microsoft-365/dev-program Import Sample Data https://learn.microsoft.com/en-us/office/developer-program/install-sample-packs Module 4 Links and Resources Since this video was uploaded, the SOF-ELK contributors have updated the way Azure and M365 logs are parsed and uploaded. They only accept JSON format, which means you will have issues uploading the CSVs without writing your own custom parser. To make this easier for you, I have created a SOF-ELK VM with the M365 logs pre-ingested that you can use for the BEC exercises later on. You can download the VM from this link below: https://drive.google.com/file/d/184kHXhZuOct0zGs0FURh7j20reBSD2t4/view?usp=sharing SOF-ELK https://github.com/philhagen/sof-elk Or download the logs used in the course as raw JSON to be parsed with your own tool here: https://drive.google.com/drive/folders/1kBRE1Lplnq04GTj5bBVjKBMcoWwPkMS4?usp=sharing Module 5 Links and Resources Enumerating via Public APIs https://o365blog.com/post/just-looking/ Non-Comprehensive list of Azure domains https://docs.microsoft.com/en-us/azure/security/fundamentals/azure-domains Determine if company is using AzureAD https://login.microsoftonline.com/getuserrealm.srf?login=username@COMPANY.onmicrosoft.com&xml=1 Get Tenant ID Using APIs https://login.microsoftonline.com//.well-known/openid-configuration User List Generation https://hunter.io/ Awesome Azure Pentest https://github.com/Kyuu-Ji/Awesome-Azure-Pentest#enumeration Cloud-Azure PayloadsAllTheThings https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Cloud%20-%20Azure%20Pentest.md AADInternals by @DrAzureAD https://o365blog.com/aadinternals/ MicroBurst (NetSPI) https://github.com/NetSPI/MicroBurst BlobHunter (CyberArk) https://github.com/cyberark/blobhunter Cloud Enum https://github.com/initstring/cloud_enum MFASweep https://github.com/dafthack/MFASweep O365Recon https://github.com/nyxgeek/o365recon AzureHound https://github.com/BloodHoundAD/AzureHound Custom Bloodhound Queries for Azure https://github.com/hausec/Bloodhound-Custom-Queries Module 6 Links and Resources Legacy Auth Deprecation: https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/deprecation-of-basic-authentication-exchange-online MSOLSpray: https://github.com/dafthack/MSOLSpray PynAuth: https://github.com/Synzack/PynAuth Application Permissions (OAuth): https://learn.microsoft.com/en-us/graph/permissions-reference Graph API Documentation: https://learn.microsoft.com/en-us/graph/api/user-get?view=graph-rest-1.0&tabs=http Microsoft Publisher Verification: https://learn.microsoft.com/en-us/azure/active-directory/develop/publisher-verification-overview ___________________ DEVICE CODE AUTHENTICATION: @DrAzureAD Blog - Device Code Authentication: https://aadinternals.com/post/phishing/#new-phishing-technique-device-code-authentication Client IDs (MSFT): https://learn.microsoft.com/en-us/troubleshoot/azure/active-directory/verify-first-party-apps-sign-in Device Login URL: https://microsoft.com/devicelogin POST Request to: https://login.microsoftonline.com/Common/oauth2/token?api-version=1.0 GRAPH API - Get Users: https://learn.microsoft.com/en-us/graph/api/user-list?view=graph-rest-1.0&tabs=http ___________________ BUSINESS EMAIL COMPROMISE: Graph Explorer: https://developer.microsoft.com/en-us/graph/graph-explorer Microsoft Graph SDK: https://learn.microsoft.com/en-us/powershell/microsoftgraph/get-started?view=graph-powershell-1.0 Graph API: https://learn.microsoft.com/en-us/graph/api/overview?view=graph-rest-1.0 For a full list of operations logged in audit logs: https://learn.microsoft.com/en-us/microsoft-365/compliance/search-the-audit-log-in-security-and-compliance?view=o365-worldwide Full list of permissions in eDiscovery auditing https://learn.microsoft.com/en-us/microsoft-365/compliance/search-for-ediscovery-activities-in-the-audit-log?view=o365-worldwide Exchange Admin Portal: https://admin.microsoft.com/AdminPortal/Home?#/users Disable Forwarding Rules: https://security.microsoft.com/ Module 7 Links and Resources GOLDEN SAML ADFS Saml Blog: https://blog.sygnia.co/detection-and-hunting-of-golden-saml-attack Export DKM Commands: https://simulandlabs.com/labs/GoldenSAML/simulation/export-adfs-dkm-key/exportADFSDKMKeyLDAP.html ADFS Configuration (AADINTERNALS) https://aadinternals.com/post/adfs/ Export ADFS Configuration: https://simulandlabs.com/labs/GoldenSAML/simulation/export-adfs-configuration/exportADFSConfigLocalNamedPipe.html Export Token Signing Certificate: https://simulandlabs.com/labs/GoldenSAML/simulation/export-adfs-certificates/exportADFSCertsDKMKey.html Forge SAML Token: https://simulandlabs.com/labs/GoldenSAML/simulation/sign-new-samltoken/README.html HTTP Request (Netwrix) https://www.netwrix.com/golden_saml_attack.html Mandiant ADFSDUMP https://github.com/mandiant/ADFSDump SACL to Detect DKM Export: https://simulandlabs.com/labs/GoldenSAML/simulation/export-adfs-dkm-key/exportADFSDKMKeyLDAP.html Enable ADFS Logging: https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/enabling-ad-fs-security-auditing-and-shipping-event-logs-to/ba-p/3610464 Revoke Refresh Tokens: https://learn.microsoft.com/en-us/powershell/module/azuread/revoke-azureaduserallrefreshtoken?view=azureadps-2.0 ________________ ATTACKING KEY VAULTS List Keys and Secrets Secrets: https://.vault.azure.net/secrets/ Keys: https://.vault.azure.net/keys/ KQL AzureDiagnostics| where ResourceProvider=="MICROSOFT.KEYVAULT"| summarize count() by CallerIPAddress, OperationName, requestUri_s ________________ SKELETON KEY Adam Chester Blog: https://blog.xpnsec.com/azuread-connect-for-redteam/ PTASpy: https://github.com/Gerenios/public/blob/master/PTASpy.cpp ________________ STEALING ACCESS TOKENS FROM OFFICE APPS @MrD0X Writeup: https://mrd0x.com/stealing-tokens-from-office-applications/ JWT Decode: https://jwt.io/ MSFT Token Tactics Writeup: https://www.microsoft.com/en-us/security/blog/2022/11/16/token-tactics-how-to-prevent-detect-and-respond-to-cloud-token-theft/ Module 8 Links and Resources PASS THE PRT Dirk Jan's Blog about PRT: https://dirkjanm.io/abusing-azure-ad-sso-with-the-primary-refresh-token/ Primary Refresh Tokens https://learn.microsoft.com/en-us/azure/active-directory/devices/concept-primary-refresh-token ROADTOKEN https://github.com/dirkjanm/ROADtoken RequestAADRefreshToken - Lee Christensen https://github.com/leechristensen/RequestAADRefreshToken/ _________________ PASS THE COOKIE Cookie Decode (Feel free to use another tool) https://github.com/byt3bl33d3r/OffensiveNim/blame/master/src/chrome_dump_bin.nim Previous Write-ups on Mimikatz method: https://www.coresecurity.com/core-labs/articles/reading-dpapi-encrypted-keys-mimikatz https://blog.netwrix.com/2022/11/29/bypassing-mfa-with-pass-the-cookie-attack/ _________________ ABUSING MANAGED IDENTITIES Managed Identities: https://learn.microsoft.com/en-us/azure/active-directory/managed-identities-azure-resources/overview @DebugPrivilege Blog: https://m365internals.com/2021/11/30/lateral-movement-with-managed-identities-of-azure-virtual-machines/ Tripla.dk WriteUp: https://tripla.dk/2022/03/13/create-an-azure-vulnerable-lab-part-4-managed-identities/ Module 9 Links and Resources PRIV ESC: USER ADMINISTRATOR User Administrator Role: https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#user-access-administrator Module 10 Links and Resources AAD FEDERATED BACKDOOR Writeup from @DrAzureAd: https://aadinternals.com/post/aadbackdoor/ Install Azure AD module: https://learn.microsoft.com/en-us/powershell/azure/active-directory/install-msonlinev1?view=azureadps-1.0#install-the-azure-ad-module Generate Free CNAME www.myo365.site _________________ MALICIOUS MFA TAKEOVER MSOnline MFA Status: https://github.com/ruudmens/LazyAdmin/blob/master/Office365/MFAStatus.ps1 Temporary Access Passes: https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-temporary-access-pass _________________ SERVICE PRINCIPAL ABUSE Conditional Access Policies: https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/workload-identity Microsoft Graph PowerShell https://learn.microsoft.com/en-us/powershell/microsoftgraph/get-started?view=graph-powershell-1.0 _________________ AUTOMATION ACCOUNT ABUSE NETSPI Owner Persist Runbook: https://github.com/NetSPI/MicroBurst/blob/master/Misc/AutomationRunbook-OwnerPersist.ps1 _________________ STORAGE ACCOUNTS Introduction to Blobs: https://docs.microsoft.com/en-us/azure/storage/blobs/storage-blobs-introduction Interact with the storage account’s containers and blobs: https://.blob.core.windows.net To interact with containers / blob objects the structure is: https://.blob.core.windows.net/container_name/file_name __________________ MALICIOUS DEVICE JOIN @DrAzureAD Writeup: https://aadinternals.com/post/devices/ POST Request: enterpriseregistration.windows.net/EnrollmentServer/device/?api-version=1.0 Malicious Device Join in the Wild (MSFT): https://www.microsoft.com/en-us/security/blog/2022/01/26/evolved-phishing-device-registration-trick-adds-to-phishers-toolbox-for-victims-without-mfa/ Module 11 Links and Resources DISABLING AUDITING Exchange Online PS Module: https://learn.microsoft.com/en-us/microsoft-365/compliance/audit-log-enable-disable?view=o365-worldwide __________________ SPOOFING AZURE SIGN-IN LOGS Secureworks Blog: https://www.secureworks.com/research/azure-active-directory-sign-ins-log-tampering https://aadinternals.com/post/hybridhealthagent/ Hybrid Health Agent @DrAzureAD https://aadinternals.com/post/hybridhealthagent/ _________________ REGISTERING FAKE AGENTS Hybrid Health Agent @DrAzureAD https://aadinternals.com/post/hybridhealthagent/