👩💻 No single pane of glass: Anatomy of an Azure permission takeover
Sysdig TRT observed an attacker use one leaked service principal (with RoleManagement.ReadWrite.Directory) to self-grant Global Administrator, then elevateAccess to root RBAC Owner, harvest storage/Event Hub/Key Vault keys, and plant backdoors on 26 app registrations.
https://www.sysdig.com/blog/no-single-pane-of-glass-anatomy-of-an-azure-permission-takeover
#azure
Post #1501
328


- ❤ 1
- 👍 1
- 🔥 1