mgeeky-Penetration-Testing-.../clouds/azure
mgeeky 4de6caaf07 Updated AzureRT 2022-01-25 12:19:14 +01:00
..
AzureRT@c194618294 Updated AzureRT 2022-01-25 12:19:14 +01:00
README.md Updated AzureRT 2022-01-25 12:19:14 +01:00

README.md

  • AzureRT - Powershell module implementing various cmdlets to interact with Azure and Azure AD from an offensive perspective. Helpful utilities dealing with access token based authentication, easily switching from Az to AzureAD and az cli interfaces, easy to use pre-made attacks such as Runbook-based command execution and more.

    Authentication & Token mechanics:

    • Get-ARTWhoami
    • Connect-ART
    • Connect-ARTAD
    • Connect-ARTADServicePrincipal
    • Get-ARTAccessTokenAzCli
    • Get-ARTAccessTokenAz
    • Get-ARTAccessTokenAzureAD
    • Parse-JWTtokenRT
    • Remove-ARTServicePrincipalKey

    Recon and Situational Awareness:

    • Get-ARTAccess
    • Get-ARTADAccess
    • Get-ARTResource
    • Get-ARTRolePermissions
    • Get-ARTADRolePermissions
    • Get-ARTRoleAssignment
    • Get-ARTKeyVaultSecrets
    • Get-ARTAutomationRunbookCode

    Privilege Escalation:

    • Add-ARTUserToGroup
    • Add-ARTUserToRole
    • Add-ARTADAppSecret

    Lateral Movement:

    • Invoke-ARTAutomationRunbook

    Misc:

    • Get-ARTUserId
    • Parse-JWTtokenRT
    • Invoke-ARTGETRequest