From 0831f1ecda861754d10aa9b7d2734e559ba9f7de Mon Sep 17 00:00:00 2001 From: Translator Date: Thu, 5 Feb 2026 12:29:39 +0000 Subject: [PATCH] Translated ['', 'src/pentesting-cloud/azure-security/az-enumeration-tool --- .../azure-security/az-enumeration-tools.md | 299 ++++++++++++++---- 1 file changed, 231 insertions(+), 68 deletions(-) diff --git a/src/pentesting-cloud/azure-security/az-enumeration-tools.md b/src/pentesting-cloud/azure-security/az-enumeration-tools.md index 5d2c497f5..46e9c6e06 100644 --- a/src/pentesting-cloud/azure-security/az-enumeration-tools.md +++ b/src/pentesting-cloud/azure-security/az-enumeration-tools.md @@ -1,11 +1,11 @@ -# Az - Enumeration Tools +# Az - 枚举工具 {{#include ../../banners/hacktricks-training.md}} -## Install PowerShell in Linux +## 在 Linux 上安装 PowerShell > [!TIP] -> 在 linux 上,您需要安装 PowerShell Core: +> 在 Linux 上需要安装 PowerShell Core: ```bash sudo apt-get update sudo apt-get install -y wget apt-transport-https software-properties-common @@ -28,11 +28,11 @@ curl -sL https://aka.ms/InstallAzureCLIDeb | sudo bash 说明来自 [**documentation**](https://learn.microsoft.com/en-us/powershell/scripting/install/installing-powershell-on-macos?view=powershell-7.4): -1. 如果尚未安装 `brew`,请安装: +1. 如果尚未安装,安装 `brew`: ```bash /bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)" ``` -2. 安装 PowerShell 的最新稳定版本: +2. 安装最新的稳定版本的 PowerShell: ```sh brew install powershell/tap/powershell ``` @@ -53,15 +53,15 @@ brew upgrade powershell Follow this link for the [**installation instructions¡**](https://learn.microsoft.com/en-us/cli/azure/install-azure-cli#install). -Commands in Azure CLI are structured using a pattern of: `az ` +在 Azure CLI 中,命令按以下模式组织: `az ` -#### 调试 | MitM az cli +#### Debug | MitM az cli -使用参数 **`--debug`** 可以看到工具 **`az`** 发送的所有请求: +使用参数 **`--debug`** 可以查看工具 **`az`** 发送的所有请求: ```bash az account management-group list --output table --debug ``` -为了对该工具进行一次 **MitM** 并手动 **检查它发送的所有请求**,你可以执行: +为了对该工具进行 **MitM** 并手动 **检查它发送的所有 requests**,你可以: {{#tabs }} {{#tab name="Bash" }} @@ -104,50 +104,215 @@ $env:HTTP_PROXY="http://127.0.0.1:8080" {{#endtab }} {{#endtabs }} +
+修复 “CA cert does not include key usage extension” + +### 为什么会发生该错误 + +当 Azure CLI 进行认证时,它会发出 HTTPS 请求(通过 MSAL → Requests → OpenSSL)。如果你使用 Burp 拦截 TLS,Burp 会为诸如 `login.microsoftonline.com` 之类的网站即时生成证书并用 Burp 的 CA 签名。 + +在较新的环境(Python 3.13 + OpenSSL 3)中,CA 验证更严格: + +- CA 证书必须包含 **Basic Constraints: `CA:TRUE`**,并具有允许签发证书的 **Key Usage** 扩展(**`keyCertSign`**,通常还包含 **`cRLSign`**)。 + +Burp 的默认 CA(PortSwigger CA)较旧,通常缺少 Key Usage 扩展,因此即便你“信任”它,OpenSSL 也会拒绝。 + +这会产生类似错误: + +- `CA cert does not include key usage extension` +- `CERTIFICATE_VERIFY_FAILED` +- `self-signed certificate in certificate chain` + +因此你必须: + +1. 创建一个现代的 CA(包含正确的 Key Usage)。 +2. 让 Burp 使用它来签发被拦截的证书。 +3. 在 macOS 中信任该 CA。 +4. 指定 Azure CLI / Requests 使用该 CA bundle。 + +### 按步骤:可行配置 + +#### 0) 前提条件 + +- 本地运行 Burp(代理在 `127.0.0.1:8080`) +- 已安装 Azure CLI(Homebrew) +- 你可以使用 `sudo`(用于在系统钥匙串中信任该 CA) + +#### 1) 创建符合标准的 Burp CA(PEM + KEY) + +创建一个明确设置 CA 扩展的 OpenSSL 配置文件: +```bash +mkdir -p ~/burp-ca && cd ~/burp-ca + +cat > burp-ca.cnf <<'EOF' +[ req ] +default_bits = 2048 +prompt = no +default_md = sha256 +distinguished_name = dn +x509_extensions = v3_ca + +[ dn ] +C = US +O = Burp Custom CA +CN = Burp Custom Root CA + +[ v3_ca ] +basicConstraints = critical,CA:TRUE +keyUsage = critical,keyCertSign,cRLSign +subjectKeyIdentifier = hash +authorityKeyIdentifier = keyid:always,issuer +EOF +``` +生成 CA certificate + private key: +```bash +openssl req -x509 -new -nodes \ +-days 3650 \ +-keyout burp-ca.key \ +-out burp-ca.pem \ +-config burp-ca.cnf +``` +健全性检查(你必须看到 Key Usage): +```bash +openssl x509 -in burp-ca.pem -noout -text | egrep -A3 "Basic Constraints|Key Usage" +``` +应包含类似以下内容: + +- `CA:TRUE` +- `Key Usage: ... Certificate Sign, CRL Sign` + +#### 2) 转换为 PKCS#12 (Burp 导入格式) + +Burp 需要证书 + 私钥,最简单是 PKCS#12: +```bash +openssl pkcs12 -export \ +-out burp-ca.p12 \ +-inkey burp-ca.key \ +-in burp-ca.pem \ +-name "Burp Custom Root CA" +``` +你会被提示设置导出密码(请设置;Burp 会要求输入该密码)。 + +#### 3) 将 CA 导入 Burp 并重启 Burp + +在 Burp 中: + +- Proxy → Options +- 找到 Import / export CA certificate +- 点击 Import CA certificate +- 选择 PKCS#12 +- 选择 `burp-ca.p12` +- 输入密码 +- 完全重启 Burp(重要) + +为什么要重启?Burp 可能在重启前一直使用旧的 CA。 + +#### 4) 在 macOS 系统钥匙串中信任新的 CA + +这将允许系统应用和许多 TLS 实现信任该 CA。 +```bash +sudo security add-trusted-cert \ +-d -r trustRoot \ +-k /Library/Keychains/System.keychain \ +~/burp-ca/burp-ca.pem +``` +(如果你更喜欢 GUI: Keychain Access → System → Certificates → import → set “Always Trust”.) + +#### 5) 配置 proxy env vars +```bash +export HTTPS_PROXY="http://127.0.0.1:8080" +export HTTP_PROXY="http://127.0.0.1:8080" +``` +#### 6) 配置 Requests/Azure CLI 以信任你的 Burp CA + +Azure CLI 在内部使用 Python Requests;设置以下两项: +```bash +export REQUESTS_CA_BUNDLE="$HOME/burp-ca/burp-ca.pem" +export SSL_CERT_FILE="$HOME/burp-ca/burp-ca.pem" +``` +注意: + +- `REQUESTS_CA_BUNDLE` 被 Requests 使用。 +- `SSL_CERT_FILE` 对其他 TLS 使用者和边缘情况有帮助。 +- 一旦 CA 正确,通常不再需要旧的 `ADAL_PYTHON_SSL_NO_VERIFY` / `AZURE_CLI_DISABLE_CONNECTION_VERIFICATION`。 + +#### 7) 验证 Burp 是否确实使用你的新 CA 进行签名(关键检查) + +这能确认你的拦截链是正确的: +```bash +openssl s_client -connect login.microsoftonline.com:443 \ +-proxy 127.0.0.1:8080 /dev/null \ +| openssl x509 -noout -issuer +``` +预期的颁发者包含你的 CA 名称,例如: + +`O=Burp Custom CA, CN=Burp Custom Root CA` + +如果你仍然看到 PortSwigger CA,Burp 没有使用你导入的 CA → 重新检查导入并重启。 + +#### 8) 验证 Python Requests 是否能通过 Burp 工作 +```bash +python3 - <<'EOF' +import requests +requests.get("https://login.microsoftonline.com") +print("OK") +EOF +``` +预期: `OK` + +#### 9) Azure CLI 测试 +```bash +az account get-access-token --resource=https://management.azure.com/ +``` +如果你已经登录,它应该返回包含 `accessToken` 的 JSON。 + +
+ ### Az PowerShell Azure PowerShell 是一个模块,包含用于从 PowerShell 命令行直接管理 Azure 资源的 cmdlets。 -有关安装说明,请参阅此链接 [**installation instructions**](https://learn.microsoft.com/en-us/powershell/azure/install-azure-powershell). +请参阅此链接以获取 [**installation instructions**](https://learn.microsoft.com/en-us/powershell/azure/install-azure-powershell)。 -Azure PowerShell AZ Module 中的命令结构如下:`-Az ` +Commands in Azure PowerShell AZ Module are structured like: `-Az ` #### Debug | MitM Az PowerShell -使用参数 **`-Debug`** 可以看到工具发送的所有请求: +使用参数 **`-Debug`** 可以看到该工具发送的所有请求: ```bash Get-AzResourceGroup -Debug ``` -为了对该工具进行 **MitM** 并 **手动检查其发送的所有请求**,你可以根据 [**docs**](https://learn.microsoft.com/en-us/powershell/azure/az-powershell-proxy) 设置环境变量 `HTTPS_PROXY` 和 `HTTP_PROXY`。 +为了对该工具执行一次 **MitM** 并手动 **检查它发送的所有请求**,你可以根据[**docs**](https://learn.microsoft.com/en-us/powershell/azure/az-powershell-proxy)设置环境变量 `HTTPS_PROXY` 和 `HTTP_PROXY`。 ### Microsoft Graph PowerShell -Microsoft Graph PowerShell 是一个跨平台 SDK,允许通过单一端点访问所有 Microsoft Graph APIs,包括 SharePoint、Exchange 和 Outlook 等服务。它支持 PowerShell 7+、通过 MSAL 的现代身份验证、外部身份和高级查询。其重点是最小权限访问,确保操作安全,并定期更新以与最新的 Microsoft Graph API 功能保持一致。 +Microsoft Graph PowerShell 是一个跨平台的 SDK,允许通过单一端点访问所有 Microsoft Graph APIs,包括 SharePoint、Exchange 和 Outlook 等服务。它支持 PowerShell 7+、通过 MSAL 的现代认证、外部身份和高级查询。注重最小权限访问,确保操作安全,并会定期更新以跟进最新的 Microsoft Graph API 功能。 -有关安装,请参阅此链接 [**installation instructions**](https://learn.microsoft.com/en-us/powershell/microsoftgraph/installation)。 +Follow this link for the [**installation instructions**](https://learn.microsoft.com/en-us/powershell/microsoftgraph/installation). -Microsoft Graph PowerShell 中的命令格式如下:`-Mg ` +Commands in Microsoft Graph PowerShell are structured like: `-Mg ` -#### Debug Microsoft Graph PowerShell +#### 调试 Microsoft Graph PowerShell -使用参数 **`-Debug`** 可以查看工具发送的所有请求: +使用参数 **`-Debug`** 可以查看该工具发送的所有请求: ```bash Get-MgUser -Debug ``` ### ~~**AzureAD Powershell**~~ -Azure Active Directory (AD) 模块现在**已弃用**,是 Azure PowerShell 的一部分,用于管理 Azure AD 资源。它提供 cmdlets 来执行诸如管理用户、组以及在 Entra ID 中注册应用程序等任务。 +Azure Active Directory (AD) 模块现在已被弃用,是 Azure PowerShell 的一部分,用于管理 Azure AD 资源。它提供用于处理诸如管理用户、组以及在 Entra ID 中应用注册等任务的 cmdlets。 > [!TIP] -> 这已被 Microsoft Graph PowerShell 取代 +> 该模块已被 Microsoft Graph PowerShell 取代 -请参阅此链接获取 [**installation instructions**](https://www.powershellgallery.com/packages/AzureAD)。 +请参阅此链接获取 [**安装说明**](https://www.powershellgallery.com/packages/AzureAD). -## 自动化 Recon & 合规 工具 + +## 自动化 Recon 与 合规工具 ### [turbot azure plugins](https://github.com/orgs/turbot/repositories?q=mod-azure) -Turbot 与 steampipe 和 powerpipe 结合,可以从 Azure 和 Entra ID 收集信息,执行合规检查并发现错误配置。当前推荐运行的 Azure 模块包括: +Turbot 与 steampipe 和 powerpipe 可用于从 Azure 和 Entra ID 收集信息、执行合规检查并发现配置错误。当前最推荐运行的 Azure 模块有: - [https://github.com/turbot/steampipe-mod-azure-compliance](https://github.com/turbot/steampipe-mod-azure-compliance) - [https://github.com/turbot/steampipe-mod-azure-insights](https://github.com/turbot/steampipe-mod-azure-insights) @@ -178,9 +343,9 @@ powerpipe server ``` ### [Prowler](https://github.com/prowler-cloud/prowler) -Prowler 是一个开源的安全工具,用于执行 AWS、Azure、Google Cloud 和 Kubernetes 的安全最佳实践评估、审计、事件响应、持续监控、加固 和 取证准备。 +Prowler 是一个开源安全工具,用于对 AWS、Azure、Google Cloud 和 Kubernetes 执行安全最佳实践评估、审计、事件响应、持续监控、加固和取证准备。 -它基本上允许我们针对 Azure 环境运行数百项检查,以发现安全配置错误,并将结果以 json(和其他文本格式)收集,或在 web 上查看。 +它基本上允许我们对 Azure 环境运行数百项检查以发现安全错误配置,并以 json(和其他文本格式)收集结果,或在 web 上查看。 ```bash # Create a application with Reader role and set the tenant ID, client ID and secret in prowler so it access the app @@ -202,7 +367,7 @@ docker run --rm -e "AZURE_CLIENT_ID=" -e "AZURE_TENANT_ID= ``` ### [Monkey365](https://github.com/silverhack/monkey365) -它可自动对 Azure subscriptions 和 Microsoft Entra ID 的安全配置进行审查。 +它可以自动执行 Azure 订阅和 Microsoft Entra ID 的安全配置审查。 HTML 报告存储在 github 仓库文件夹内的 `./monkey-reports` 目录中。 ```bash @@ -225,7 +390,7 @@ Invoke-Monkey365 -TenantId -ClientId -ClientSecret $Secu ``` ### [ScoutSuite](https://github.com/nccgroup/ScoutSuite) -ScoutSuite 收集配置数据以供人工检查,并标出风险区域。它是一个多云的安全审计工具,可用于评估云环境的安全态势。 +Scout Suite 收集配置数据以供人工检查并突出风险区域。它是一个多云安全审计工具,能够对云环境的安全态势进行评估。 ```bash virtualenv -p python3 venv source venv/bin/activate @@ -241,9 +406,9 @@ python scout.py azure --cli ``` ### [Azure-MG-Sub-Governance-Reporting](https://github.com/JulianHayward/Azure-MG-Sub-Governance-Reporting) -这是一个 powershell 脚本,帮助你 **可视化 Management Group 和 Entra ID** 租户中所有资源和权限,并发现安全配置错误。 +这是一个 powershell 脚本,帮助你 **可视化 Management Group 和 Entra ID 租户内的所有资源与权限** 并发现安全配置错误。 -它使用 Az PowerShell module,因此任何由该模块支持的身份验证方式都可用。 +它通过 Az PowerShell module 工作,因此该工具支持的任何身份验证方式均受支持。 ```bash import-module Az .\AzGovVizParallel.ps1 -ManagementGroupId [-SubscriptionIdWhitelist ] @@ -252,7 +417,7 @@ import-module Az ### [**ROADRecon**](https://github.com/dirkjanm/ROADtools) -ROADRecon 的枚举提供关于 Entra ID 配置的信息,例如用户、组、角色、条件访问策略... +ROADRecon 的枚举提供有关 Entra ID 配置的信息,例如 users、groups、roles、conditional access policies... ```bash cd ROADTools pipenv shell @@ -265,21 +430,21 @@ roadrecon gui ``` ### [**AzureHound**](https://github.com/BloodHoundAD/AzureHound) -AzureHound 是用于 Microsoft Entra ID 和 Azure 的 BloodHound 采集器。它是一个单一静态的 Go 二进制文件,可在 Windows/Linux/macOS 上运行,直接与以下服务通信: +AzureHound 是用于 Microsoft Entra ID 和 Azure 的 BloodHound 收集器。它是一个针对 Windows/Linux/macOS 的静态 Go 二进制,直接与下列服务通信: - Microsoft Graph (Entra ID directory, M365) and -- Azure Resource Manager (ARM) 控制平面 (subscriptions, resource groups, compute, storage, key vault, app services, AKS, etc.) +- Azure Resource Manager (ARM) control plane (subscriptions, resource groups, compute, storage, key vault, app services, AKS, etc.) -主要特性 -- 可从公共互联网的任何位置针对租户 APIs 运行(不需要内部网络访问) -- 输出 JSON 以供 BloodHound CE 摄取,用于可视化跨身份和云资源的攻击路径 -- 观察到的默认 User-Agent:azurehound/v2.x.x +主要特征 +- 可从公共互联网的任何位置对租户 APIs 发起请求(不需要内部网络访问) +- 输出 JSON 供 BloodHound CE 导入,以可视化跨身份与云资源的攻击路径 +- 默认 User-Agent:azurehound/v2.x.x 认证选项 -- 用户名 + 密码: -u -p -- 刷新令牌: --refresh-token -- JSON Web Token(访问令牌): --jwt -- 服务主体 密钥: -a -s -- 服务主体 证书: -a --cert --key [--keypass ] +- 用户名 + 密码:-u -p +- 刷新令牌:--refresh-token +- JSON Web Token(访问令牌):--jwt +- 服务主体密钥:-a -s +- 服务主体证书:-a --cert --key [--keypass ] 示例 ```bash @@ -317,36 +482,36 @@ azurehound list web-apps -t "" -o webapps.json azurehound list function-apps -t "" -o funcapps.json ``` What gets queried -- Graph endpoints (examples): +- Graph endpoints(示例): - /v1.0/organization, /v1.0/users, /v1.0/groups, /v1.0/roleManagement/directory/roleDefinitions, directoryRoles, owners/members -- ARM endpoints (examples): +- ARM endpoints(示例): - management.azure.com/subscriptions/.../providers/Microsoft.Storage/storageAccounts - .../Microsoft.KeyVault/vaults, .../Microsoft.Compute/virtualMachines, .../Microsoft.Web/sites, .../Microsoft.ContainerService/managedClusters Preflight behavior and endpoints -- 每个 azurehound list 通常在枚举前执行这些测试调用: -1) Identity platform: login.microsoftonline.com -2) Graph: GET https://graph.microsoft.com/v1.0/organization -3) ARM: GET https://management.azure.com/subscriptions?api-version=... -- Cloud environment base URLs 在 Government/China/Germany 环境下有所不同。参见仓库中的 constants/environments.go。 +- 每个 azurehound list 通常在 enumeration 之前执行这些测试调用: +1) 身份平台:login.microsoftonline.com +2) Graph:GET https://graph.microsoft.com/v1.0/organization +3) ARM:GET https://management.azure.com/subscriptions?api-version=... +- Cloud environment 基础 URL 在 Government/China/Germany 存在差异。查看 repo 中的 constants/environments.go。 ARM-heavy objects (less visible in Activity/Resource logs) -- 以下目标主要使用 ARM control plane 读取:automation-accounts, container-registries, function-apps, key-vaults, logic-apps, managed-clusters, management-groups, resource-groups, storage-accounts, storage-containers, virtual-machines, vm-scale-sets, web-apps。 -- 这些 GET/list 操作通常不会写入 Activity Logs;数据平面读取(例如 *.blob.core.windows.net, *.vault.azure.net)由资源级别的 Diagnostic Settings 覆盖。 +- 以下列表的目标主要使用 ARM control plane 读取:automation-accounts, container-registries, function-apps, key-vaults, logic-apps, managed-clusters, management-groups, resource-groups, storage-accounts, storage-containers, virtual-machines, vm-scale-sets, web-apps。 +- 这些 GET/list 操作通常不会写入 Activity Logs;data-plane 读取(例如 *.blob.core.windows.net, *.vault.azure.net)由资源级别的 Diagnostic Settings 覆盖。 OPSEC and logging notes -- Microsoft Graph Activity Logs 默认未启用;启用并导出到 SIEM 以便获得对 Graph 调用的可见性。预期的 Graph preflight GET /v1.0/organization 会带有 UA azurehound/v2.x.x。 +- Microsoft Graph Activity Logs 默认未启用;启用并导出到 SIEM 以便可见 Graph 调用。预期会看到带有 UA azurehound/v2.x.x 的 Graph preflight GET /v1.0/organization。 - Entra ID non-interactive sign-in logs 会记录 AzureHound 使用的 identity platform auth (login.microsoftonline.com)。 -- ARM control-plane 的 read/list 操作不会记录在 Activity Logs 中;许多 azurehound 针对资源的 list 操作不会显示在那里。只有数据平面日志(通过 Diagnostic Settings)会捕获对服务端点的读取。 -- Defender XDR GraphApiAuditEvents (preview) 可能会暴露 Graph 调用和 token 标识符,但可能缺少 UserAgent 且保留时间有限。 +- ARM control-plane 的 read/list 操作不会记录在 Activity Logs;许多针对资源的 azurehound list 操作不会出现在那里。只有通过 Diagnostic Settings 的 data-plane 日志会捕获到对服务端点的读取。 +- Defender XDR GraphApiAuditEvents (preview) 可以暴露 Graph 调用和 token identifiers,但可能缺少 UserAgent 且保留期限有限。 -Tip: 在为权限路径进行枚举时,导出 users、groups、roles 和 role assignments,然后导入 BloodHound 并使用预置的 cypher queries 来显示 Global Administrator/Privileged Role Administrator 以及通过嵌套组和 RBAC 分配的传递式提升路径。 +Tip: 在为 privilege paths 进行 enumeration 时,导出 users、groups、roles 和 role assignments,然后导入 BloodHound,使用预构建的 cypher queries 来揭示 Global Administrator/Privileged Role Administrator 以及通过嵌套组和 RBAC 分配的传递性提权路径。 -Launch the BloodHound web with `curl -L https://ghst.ly/getbhce | docker compose -f - up` and import the `output.json` file. Then, in the EXPLORE tab, in the CYPHER section you can see a folder icon that contains pre-built queries. +启动 BloodHound web:`curl -L https://ghst.ly/getbhce | docker compose -f - up` 并导入 `output.json` 文件。然后在 EXPLORE 选项卡的 CYPHER 部分,你可以看到包含预构建查询的文件夹图标。 ### [**MicroBurst**](https://github.com/NetSPI/MicroBurst) -MicroBurst 包含函数和脚本,支持 Azure Services 的发现、弱配置审计,以及 post exploitation 操作(例如 credential dumping)。它旨在在存在 Azure 的 penetration tests 期间使用。 +MicroBurst 包含支持 Azure Services 发现、弱配置审计以及 post exploitation 操作(例如 credential dumping)的函数和脚本。它旨在在使用 Azure 的 penetration tests 中使用。 ```bash Import-Module .\MicroBurst.psm1 Import-Module .\Get-AzureDomainInfo.ps1 @@ -354,9 +519,9 @@ Get-AzureDomainInfo -folder MicroBurst -Verbose ``` ### [**PowerZure**](https://github.com/hausec/PowerZure) -PowerZure 的出现源于对一个能够同时进行 reconnaissance 和 exploitation 的框架的需求,针对 Azure、EntraID 及其相关资源。 +PowerZure 的创建源于对一个框架的需求,该框架既能对 Azure、EntraID 及其相关资源执行 reconnaissance and exploitation。 -它使用 **Az PowerShell** 模块,因此任何该模块支持的 authentication 方法也被该工具支持。 +它使用 **Az PowerShell** 模块,因此任何 Az PowerShell 支持的身份验证方式也被该工具支持。 ```bash # Login Import-Module Az @@ -387,7 +552,7 @@ Invoke-AzureRunCommand -Command -VMName ``` ### [**GraphRunner**](https://github.com/dafthack/GraphRunner/wiki/Invoke%E2%80%90GraphRunner) -GraphRunner 是一个用于与 Microsoft Graph API 交互的 post-exploitation 工具集。它提供了各种工具,用于从 Microsoft Entra ID (Azure AD) 帐户执行 reconnaissance、persistence 和 pillaging of data。 +GraphRunner 是一个用于与 Microsoft Graph API 交互的 post-exploitation 工具集。它提供了多种工具,用于对 Microsoft Entra ID (Azure AD) 帐户执行 reconnaissance、persistence 以及 pillaging 数据。 ```bash #A good place to start is to authenticate with the Get-GraphTokens module. This module will launch a device-code login, allowing you to authenticate the session from a browser session. Access and refresh tokens will be written to the global $tokens variable. To use them with other GraphRunner modules use the Tokens flag (Example. Invoke-DumpApps -Tokens $tokens) Import-Module .\GraphRunner.ps1 @@ -431,11 +596,9 @@ Invoke-GraphRunner -Tokens $tokens ``` ### [Stormspotter](https://github.com/Azure/Stormspotter) -Stormspotter 为 Azure 订阅中的资源创建“攻击图”。 +Stormspotter 会为 Azure 订阅中的资源创建一个“attack graph”。它使 red teams 和 pentesters 能够可视化租户内的 attack surface 和 pivot 机会,并大幅提升防御人员快速定位和优先处理 incident response 工作的能力。 -它使 red teams and pentesters 能可视化 tenant 中的攻击面和横向移动机会,并大幅提升你的防御者快速定位和优先排序事件响应工作的能力。 - -**不幸的是,看起来已不再维护** +**不幸的是,似乎已不再维护。** ```bash # Start Backend cd stormspotter\backend\ @@ -453,11 +616,11 @@ az login -u test@corp.onmicrosoft.com -p Welcome2022! python stormspotter\stormcollector\sscollector.pyz cli # This will generate a .zip file to upload in the frontend (127.0.0.1:9091) ``` -## 参考资料 -- [Cloud Discovery With AzureHound (Unit 42)](https://unit42.paloaltonetworks.com/threat-actor-misuse-of-azurehound/) -- [AzureHound repository](https://github.com/SpecterOps/AzureHound) -- [BloodHound repository](https://github.com/SpecterOps/BloodHound) -- [AzureHound Community Edition Flags](https://bloodhound.specterops.io/collect-data/ce-collection/azurehound-flags) +## 参考 +- [使用 AzureHound 的云发现 (Unit 42)](https://unit42.paloaltonetworks.com/threat-actor-misuse-of-azurehound/) +- [AzureHound 仓库](https://github.com/SpecterOps/AzureHound) +- [BloodHound 仓库](https://github.com/SpecterOps/BloodHound) +- [AzureHound 社区版 标志](https://bloodhound.specterops.io/collect-data/ce-collection/azurehound-flags) - [AzureHound constants/environments.go](https://github.com/SpecterOps/AzureHound/blob/main/constants/environments.go) - [AzureHound client/storage_accounts.go](https://github.com/SpecterOps/AzureHound/blob/main/client/storage_accounts.go) - [AzureHound client/roles.go](https://github.com/SpecterOps/AzureHound/blob/main/client/roles.go)