Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Added some queries related to Azure #666

Closed
wants to merge 20 commits into from

Conversation

LuemmelSec
Copy link
Contributor

As the build in queries were having no entries for Azure related stuff I implemented some that I recently used when walking myself through several attack paths in Azure environments.

They have all been sorted into according categories for a better overview.

image
image
image

Feel free to select the ones that make sense to you guys or seem to be useful.

@JonasBK JonasBK changed the base branch from master to 4.3.1 May 13, 2023 03:55
Return All Azure Users and their Groups was wrong from a syntax point but also when correctly written gives not much value.
Fixed "Return All Azure AD Groups that are synchronized with On-Premise AD" group
I was dumb and did some copy pasta for the "Return all Service Principals that are a Managed Identity an have a path to a Key Vault" query. Now fixed.
New query:
Return all paths to Azure Keyvaults from owned principals
Added query: "Return all Azure Users with a Path to High Value Targets"
@JonasBK JonasBK deleted the branch SpecterOps:4.3.1 May 23, 2023 14:32
@JonasBK JonasBK closed this May 23, 2023
@LuemmelSec LuemmelSec deleted the Querie-Extension branch May 23, 2023 19:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants