Back

Azure Penetration Testing Specialist
In-person

This course is designed to introduce beginners to the fundamentals of Azure penetration testing, equipping them with essential knowledge and skills to assess and secure Azure cloud environments.

Tarek

Lead Trainer

48 hr

Description

Course Curriculum

Introduction to Azure

3 lessons

Intro to Azure

Intro to Azure services

Different ways to interact with Azure

Reconnaissance and Enumeration

4 lessons

Tenant availability and gathering tenant information

Azure subdomains recon

Enumerating services

User enumeration

Initial Access

4 lessons

Password spraying

Consent phishing

Device Code Phishing

Adversary in the Middle

Bypassing Defenses

3 lessons

Bypassing MFA

Understanding conditional access

Bypassing conditional access

Tokens

3 lessons

Understanding different token types

Where to look for tokens

How can different tokens be used and abused

Entra ID Persistence

4 lessons

Understanding Entra ID roles and permissions

Understanding users, groups and service principles

Abusing external collaboration for persistence

Abusing service principles for persistence

Attacking Storage

4 lessons

Understanding storage types

Storage enumeration

Connecting to containers and blobs

Connecting to storage accounts

Attacking Automation Accounts

4 lessons

Understanding automation accounts

Understanding runbooks

Finding and decoding secrets

Persistence with automation accounts

Attacking VMs

3 lessons

Abusing disk snapshots

Abusing run commands

Abusing IMDS

Attacking Key Vaults

3 lessons

Abusing key vault policies

Abusing key vault RBAC

Retrieving secrets from key vaults

Abusing Container Registries

4 lessons

Container lifecycle

Registry anonymous access

Registry admin access

Inspecting images