Translated ['', 'src/pentesting-cloud/azure-security/az-enumeration-tool

This commit is contained in:
Translator
2026-05-26 19:12:21 +00:00
parent dc1b6abd34
commit 0f01d49d2d
@@ -26,13 +26,13 @@ curl -sL https://aka.ms/InstallAzureCLIDeb | sudo bash
```
## MacOS에 PowerShell 설치
다음은 [**documentation**](https://learn.microsoft.com/en-us/powershell/scripting/install/installing-powershell-on-macos?view=powershell-7.4)에서 가져온 지침입니다:
[**documentation**](https://learn.microsoft.com/en-us/powershell/scripting/install/installing-powershell-on-macos?view=powershell-7.4)의 지침:
1. 아직 설치되어 있지 않다면 `brew`를 설치하세요:
1. 아직 설치되지 않다면 `brew`를 설치하세요:
```bash
/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"
```
2. 최신 안정 버전의 PowerShell을 설치하세요:
2. PowerShell의 최신 안정 버전을 설치합니다:
```sh
brew install powershell/tap/powershell
```
@@ -45,23 +45,23 @@ pwsh
brew update
brew upgrade powershell
```
## 주요 열거 도구
## Main Enumeration Tools
### az cli
[**Azure Command-Line Interface (CLI)**](https://learn.microsoft.com/en-us/cli/azure/install-azure-cli) 는 Python으로 작성된 크로스 플랫폼 도구로, (대부분의) Azure 및 Entra ID 리소스를 관리 운영하는 데 사용됩니다. 명령줄이나 스크립트를 통해 Azure에 연결하고 관리 명령을 실행합니다.
[**Azure Command-Line Interface (CLI)**](https://learn.microsoft.com/en-us/cli/azure/install-azure-cli) 는 Python으로 작성된 크로스 플랫폼 도구로, (대부분의) Azure 및 Entra ID 리소스를 관리하고 운영하는 데 사용됩니다. Azure에 연결하여 명령줄이나 스크립트를 통해 관리 명령을 실행합니다.
설치는 다음 링크를 참고하세요: [**installation instructions¡**](https://learn.microsoft.com/en-us/cli/azure/install-azure-cli#install).
[**설치 지침¡**](https://learn.microsoft.com/en-us/cli/azure/install-azure-cli#install) 은 이 링크를 따라가세요.
Azure CLI의 명령은 다음 패턴으로 구성됩니다: `az <service> <action> <parameters>`
#### 디버그 | MitM az cli
#### Debug | MitM az cli
파라미터 **`--debug`**를 사용하면 도구 **`az`**가 전송하는 모든 요청을 볼 수 있습니다:
파라미터 **`--debug`** 를 사용하면 도구 **`az`** 보내는 모든 요청을 볼 수 있습니다:
```bash
az account management-group list --output table --debug
```
도구에 **MitM**을 수행하고 도구가 보내는 모든 **check all the requests**를 수동으로 확인하려면 다음을 수행할 수 있습니다:
In order to do a **MitM** to the tool and **check all the requests** it's sending manually you can do:
{{#tabs }}
{{#tab name="Bash" }}
@@ -105,42 +105,42 @@ $env:HTTP_PROXY="http://127.0.0.1:8080"
{{#endtabs }}
<details>
<summary><strong>Fixing “CA cert does not include key usage extension”</strong></summary>
<summary><strong>“CA cert does not include key usage extension” 수정</strong></summary>
### Why the error happens
### 왜 이 오류가 발생하는가
When Azure CLI authenticates, it makes HTTPS requests (via MSAL → Requests → OpenSSL). If youre intercepting TLS with Burp, Burp generates “on the fly” certificates for sites like `login.microsoftonline.com` and signs them with Burps CA.
Azure CLI가 인증할 때 HTTPS 요청을 보냅니다 (MSAL → Requests → OpenSSL). Burp로 TLS를 intercept 중이면, Burp는 `login.microsoftonline.com` 같은 사이트에 대해 “on the fly” certificates를 생성하고 Burp CA로 서명합니다.
On newer stacks (Python 3.13 + OpenSSL 3), CA validation is stricter:
새로운 스택(Python 3.13 + OpenSSL 3)에서는 CA validation이 더 엄격합니다:
- A CA certificate must include **Basic Constraints: `CA:TRUE`** and a **Key Usage** extension permitting certificate signing (**`keyCertSign`**, and typically **`cRLSign`**).
- CA certificate **Basic Constraints: `CA:TRUE`**와 certificate signing을 허용하는 **Key Usage** extension을 포함해야 합니다 (**`keyCertSign`**, 그리고 보통 **`cRLSign`**).
Burps default CA (PortSwigger CA) is old and typically lacks the Key Usage extension, so OpenSSL rejects it even if you “trust it”.
Burp의 기본 CA(PortSwigger CA)는 오래되었고 일반적으로 Key Usage extension이 없어서, OpenSSL은 심지어 그것을 “trust”하더라도 거부합니다.
That produces errors like:
그 결과 다음과 같은 오류가 발생합니다:
- `CA cert does not include key usage extension`
- `CERTIFICATE_VERIFY_FAILED`
- `self-signed certificate in certificate chain`
So you must:
따라서 다음이 필요합니다:
1. Create a modern CA (with proper Key Usage).
2. Make Burp use it to sign intercepted certs.
3. Trust that CA in macOS.
4. Point Azure CLI / Requests to that CA bundle.
1. 올바른 Key Usage가 포함된 modern CA를 만듭니다.
2. Burp가 이를 사용해 intercepted certs를 서명하게 합니다.
3. macOS에서 그 CA를 trust합니다.
4. Azure CLI / Requests가 그 CA bundle을 사용하도록 지정합니다.
### Step-by-step: working configuration
### 단계별: working configuration
#### 0) Prereqs
- Burp running locally (proxy at `127.0.0.1:8080`)
- Azure CLI installed (Homebrew)
- You can `sudo` (to trust the CA in the system keychain)
- Burp가 로컬에서 실행 중이어야 함 (proxy: `127.0.0.1:8080`)
- Azure CLI가 설치되어 있어야 함 (Homebrew)
- `sudo`를 사용할 수 있어야 함 (시스템 keychain에 CA를 trust하기 위해)
#### 1) Create a standards-compliant Burp CA (PEM + KEY)
#### 1) standards-compliant Burp CA 만들기 (PEM + KEY)
Create an OpenSSL config file that explicitly sets CA extensions:
CA extensions를 명시적으로 설정하는 OpenSSL config file을 만듭니다:
```bash
mkdir -p ~/burp-ca && cd ~/burp-ca
@@ -164,7 +164,7 @@ subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid:always,issuer
EOF
```
CA 인증서 + 개인 키 생성:
CA 인증서 + private key 생성:
```bash
openssl req -x509 -new -nodes \
-days 3650 \
@@ -172,18 +172,18 @@ openssl req -x509 -new -nodes \
-out burp-ca.pem \
-config burp-ca.cnf
```
정상성 검사(반드시 Key Usage를 확인하세요):
Sanity check (Key Usage를 반드시 확인하세요):
```bash
openssl x509 -in burp-ca.pem -noout -text | egrep -A3 "Basic Constraints|Key Usage"
```
다음과 같은 항목이 포함되어야 합니다:
예상되는 항목은 다음과 같습니다:
- `CA:TRUE`
- `Key Usage: ... Certificate Sign, CRL Sign`
#### 2) PKCS#12로 변환 (Burp import format)
#### 2) PKCS#12로 변환하기 (Burp import format)
Burp는 certificate + private key가 필요하, 가장 쉬운 형식은 PKCS#12입니다:
Burp는 certificate + private key가 필요하므로, 가장 쉬운 방법은 PKCS#12 형식입니다:
```bash
openssl pkcs12 -export \
-out burp-ca.p12 \
@@ -191,64 +191,66 @@ openssl pkcs12 -export \
-in burp-ca.pem \
-name "Burp Custom Root CA"
```
#### 3) CA를 Burp에 임포트하고 Burp 재시작
내보내기 비밀번호를 입력하라는 메시지가 표시됩니다(하나 설정하세요; Burp가 요청할 것입니다).
#### 3) CA를 Burp에 import하고 Burp를 restart
Burp에서:
- Proxy → Options
- Import / export CA certificate 항목을 찾기
- Import CA certificate 클릭
- Choose PKCS#12
- Select `burp-ca.p12`
- 비밀번호 입력
- Burp를 완전히 재시작 (중요)
- Import / export CA certificate를 찾습니다
- Import CA certificate 클릭합니다
- PKCS#12 선택합니다
- `burp-ca.p12`를 선택합니다
- 비밀번호 입력합니다
- Burp를 완전히 restart합니다(중요)
재시작하나요? Burp는 재시작할 때까지 이전 CA를 계속 사용할 수 있습니다.
restart하나요? Burp는 restart 전까지 이전 CA를 계속 사용할 수 있습니다.
#### 4) macOS 시스템 키체인에서 새 CA 신뢰
#### 4) macOS system keychain에서 새 CA를 trust
작업으로 시스템 앱과 많은 TLS 스택이 해당 CA를 신뢰하게 됩니다.
렇게 하면 system apps와 많은 TLS stack이 CA를 trust할 수 있습니다.
```bash
sudo security add-trusted-cert \
-d -r trustRoot \
-k /Library/Keychains/System.keychain \
~/burp-ca/burp-ca.pem
```
(만약 GUI를 선호한다면: Keychain Access → System → Certificates → import → “Always Trust”로 설정하세요.)
(If you prefer GUI: Keychain Access → System → Certificates → import → set “Always Trust”.)
#### 5) 프록시 환경 변수 구성
#### 5) 프록시 env vars 구성
```bash
export HTTPS_PROXY="http://127.0.0.1:8080"
export HTTP_PROXY="http://127.0.0.1:8080"
```
#### 6) Requests/Azure CLI가 Burp CA를 신뢰하도록 구성
#### 6) Requests/Azure CLI가 Burp CA를 신뢰하도록 구성하기
Azure CLI는 내부적으로 Python Requests를 사용합니다; 둘 다 설정하세요:
Azure CLI는 내부적으로 Python Requests를 사용하므로, 다음 두 가지를 모두 설정한다:
```bash
export REQUESTS_CA_BUNDLE="$HOME/burp-ca/burp-ca.pem"
export SSL_CERT_FILE="$HOME/burp-ca/burp-ca.pem"
```
참고:
Notes:
- `REQUESTS_CA_BUNDLE` Requests에서 사용됩니다.
- `SSL_CERT_FILE` 다른 TLS 클라이언트와 특수한 경우에 도움이 됩니다.
- CA가 올바르면 일반적으로 이전의 `ADAL_PYTHON_SSL_NO_VERIFY` / `AZURE_CLI_DISABLE_CONNECTION_VERIFICATION`는 필요하지 않습니다.
- `REQUESTS_CA_BUNDLE` Requests에서 사용됩니다.
- `SSL_CERT_FILE` 다른 TLS consumers와 edge cases에 도움이 됩니다.
- CA가 올바르면 보통 더 이상 예전 `ADAL_PYTHON_SSL_NO_VERIFY` / `AZURE_CLI_DISABLE_CONNECTION_VERIFICATION`는 필요하지 않습니다.
#### 7) Burp가 실제로 새로운 CA로 서명하고 있는지 확인하기 (중요 확인)
#### 7) Verify Burp is actually signing with your new CA (critical check)
이것으로 인터셉션 체인이 올바른지 확인합니다:
이것은 interception chain이 올바른지 확인합니다:
```bash
openssl s_client -connect login.microsoftonline.com:443 \
-proxy 127.0.0.1:8080 </dev/null 2>/dev/null \
| openssl x509 -noout -issuer
```
예상 발급자(issuer)에는 귀하의 CA 이름이 포함되어야 합니다. 예:
예상되는 issuer에는 CA 이름이 포함니다. 예:
`O=Burp Custom CA, CN=Burp Custom Root CA`
여전히 PortSwigger CA가 보면, Burp가 가져온 CA를 사용하고 있지 않습니다 → 가져오기를 다시 확인하고 재시작하세요.
여전히 PortSwigger CA가 보인다면, Burp가 가져온 CA를 사용하지 않는 것입니다 → import를 다시 확인하고 restart하세요.
#### 8) Python Requests가 Burp를 통해 동하는지 확인
#### 8) Python Requests가 Burp를 통해 동하는지 확인하기
```bash
python3 - <<'EOF'
import requests
@@ -256,61 +258,61 @@ requests.get("https://login.microsoftonline.com")
print("OK")
EOF
```
예상: `OK`
Expected: `OK`
#### 9) Azure CLI 테스트
#### 9) Azure CLI test
```bash
az account get-access-token --resource=https://management.azure.com/
```
이미 로그인되어 있으면 `accessToken` 포함 JSON을 반환해야 합니다.
이미 로그인되어 있다면, `accessToken` 포함 JSON을 반환해야 합니다.
</details>
### Az PowerShell
Azure PowerShell은 PowerShell 명령줄에서 Azure 리소스를 직접 관리하기 위한 cmdlets가 포함된 모듈입니다.
Azure PowerShell은 PowerShell command line에서 직접 Azure resources를 관리하기 위한 cmdlets 모듈입니다.
설치 지침은 다음 링크를 참고하세요: [**installation instructions**](https://learn.microsoft.com/en-us/powershell/azure/install-azure-powershell).
[**installation instructions**](https://learn.microsoft.com/en-us/powershell/azure/install-azure-powershell)를 따라가세요.
Azure PowerShell AZ Module의 명령은 다음과 같 구성됩니다: `<Action>-Az<Service> <parameters>`
Azure PowerShell AZ Module의 명령은 다음과 같은 형식으로 구성됩니다: `<Action>-Az<Service> <parameters>`
#### Debug | MitM Az PowerShell
파라미터 **`-Debug`**를 사용하면 도구가 전송하는 모든 요청을 볼 수 있습니다:
**`-Debug`** 파라미터를 사용하면 tool이 보내는 모든 requests를 볼 수 있습니다:
```bash
Get-AzResourceGroup -Debug
```
도구에 대해 **MitM**를 수행하고 전송하는 모든 요청을 수동으로 확인하려면 환경 변수 `HTTPS_PROXY``HTTP_PROXY` [**docs**](https://learn.microsoft.com/en-us/powershell/azure/az-powershell-proxy)에 따라 설정할 수 있습니다.
In order to do a **MitM** to the tool and **check all the requests** it's sending manually you can set the env variables `HTTPS_PROXY` and `HTTP_PROXY` according to the [**docs**](https://learn.microsoft.com/en-us/powershell/azure/az-powershell-proxy).
### Microsoft Graph PowerShell
Microsoft Graph PowerShell은 단일 엔드포인트를 사용해 SharePoint, Exchange, Outlook 같은 서비스를 포함한 모든 Microsoft Graph API에 접근할 수 있게 하는 크로스-플랫폼 SDK입니다. PowerShell 7+를 지원하며, MSAL을 통한 현대적 인증, 외부 identities, 고급 쿼리를 지원합니다. 최소 권한 접근을 중시하여 안전한 운영을 보장하고 최신 Microsoft Graph API 기능에 맞춰 정기적으로 업데이트됩니다.
Microsoft Graph PowerShell is a cross-platform SDK that enables access to all Microsoft Graph APIs, including services like SharePoint, Exchange, and Outlook, using a single endpoint. It supports PowerShell 7+, modern authentication via MSAL, external identities, and advanced queries. With a focus on least privilege access, it ensures secure operations and receives regular updates to align with the latest Microsoft Graph API features.
Follow this link for the [**installation instructions**](https://learn.microsoft.com/en-us/powershell/microsoftgraph/installation).
Microsoft Graph PowerShell의 명령은 다음과 같은 형식입니다: `<Action>-Mg<Service> <parameters>`
Commands in Microsoft Graph PowerShell are structured like: `<Action>-Mg<Service> <parameters>`
#### Debug Microsoft Graph PowerShell
파라미터 **`-Debug`**를 사용하면 도구가 전송하는 모든 요청을 확인할 수 있습니다:
Using the parameter **`-Debug`** it's possible to see all the requests the tool is sending:
```bash
Get-MgUser -Debug
```
### ~~**AzureAD Powershell**~~
Azure Active Directory (AD) 모듈은 현재 **사용 중단됨** 상태이며, Azure AD 리소스 관리 위한 Azure PowerShell의 일부입니다. 이 모듈은 Entra ID에서 사용자, 그룹 및 애플리케이션 등록 관리를 비롯한 작업을 수행하기 위한 cmdlets를 제공합니다.
Azure Active Directory (AD) module은 현재 **deprecated**되었으며, Azure AD 리소스 관리하기 위한 Azure PowerShell의 일부입니다. 사용자, 그룹, application registrations를 Entra ID에서 관리하는 것과 같은 작업을 위한 cmdlets를 제공합니다.
> [!TIP]
> 이는 Microsoft Graph PowerShell로 대체되었습니다
설치 지침은 다음 링크를 참조하세요: [**installation instructions**](https://www.powershellgallery.com/packages/AzureAD).
[**installation instructions**](https://www.powershellgallery.com/packages/AzureAD) 링크를 따라가세요.
## 자동화된 Recon Compliance 도구
## Automated Recon & Compliance Tools
### [turbot azure plugins](https://github.com/orgs/turbot/repositories?q=mod-azure)
Turbot은 steampipe powerpipe와 함께 Azure Entra ID에서 정보를 수집하고 컴플라이언스 검사 및 잘못된 구성(misconfigurations)을 찾아냅니다. 현재 권장되는 Azure 모듈은 다음과 같습니다:
steampipe powerpipe를 사용하는 Turbot은 Azure Entra ID에서 정보를 수집하고, compliance checks를 수행하며 misconfigurations를 찾을 수 있게 해줍니다. 현재 가장 권장되는 Azure modules는 다음과 같습니다:
- [https://github.com/turbot/steampipe-mod-azure-compliance](https://github.com/turbot/steampipe-mod-azure-compliance)
- [https://github.com/turbot/steampipe-mod-azure-insights](https://github.com/turbot/steampipe-mod-azure-insights)
@@ -341,9 +343,9 @@ powerpipe server
```
### [Prowler](https://github.com/prowler-cloud/prowler)
Prowler는 AWS, Azure, Google Cloud 및 Kubernetes에 대한 보안 모범 사례 평가, 감사, 사고 대응, 지속적인 모니터링, 하드닝 및 포렌식 준비를 수행하기 위한 오픈 소스 보안 도구입니다.
Prowler는 AWS, Azure, Google Cloud 및 Kubernetes의 security best practices 평가, 감사, incident response, continuous monitoring, hardening, forensics readiness를 수행하기 위한 Open Source security tool입니다.
기본적으로 Azure 환경에서 수백 가지 검사를 실행하여 보안 구성 오류를 찾 결과를 json (및 기타 텍스트 형식)으로 수집하거나 에서 확인할 수 있게 해줍니다.
기본적으로 Azure environment에 대해 수백 개의 checks를 실행해 security misconfigurations를 찾고, 결과를 json(및 다른 text format)으로 수집하거나 web에서 확인할 수 있게 해줍니다.
```bash
# Create a application with Reader role and set the tenant ID, client ID and secret in prowler so it access the app
@@ -365,9 +367,9 @@ docker run --rm -e "AZURE_CLIENT_ID=<client-id>" -e "AZURE_TENANT_ID=<tenant-id>
```
### [Monkey365](https://github.com/silverhack/monkey365)
자동으로 Azure 구독 및 Microsoft Entra ID 보안 구성 검토를 수행할 수 있습니다.
Azure subscriptions 및 Microsoft Entra ID 보안 구성 검토를 자동으로 수행할 수 있습니다.
HTML 보고서는 github 저장소 폴더 내의 `./monkey-reports` 디렉리에 저장됩니다.
HTML 보고서는 github repository 폴더 내`./monkey-reports` 디렉리에 저장됩니다.
```bash
git clone https://github.com/silverhack/monkey365
Get-ChildItem -Recurse monkey365 | Unblock-File
@@ -388,7 +390,7 @@ Invoke-Monkey365 -TenantId <tenant-id> -ClientId <client-id> -ClientSecret $Secu
```
### [ScoutSuite](https://github.com/nccgroup/ScoutSuite)
Scout Suite는 수동 검사를 위해 구성 데이터를 수집하고 위험 영역을 강조합니다. 멀티클라우드 환경을 대상으로 하는 보안 감사 도구로, 클라우드 환경의 보안 상태 평가를 가능하게 합니다.
Scout Suite는 수동 검사를 위한 configuration 데이터를 수집하고 risk area를 강조 표시합니다. 이는 multi-cloud security-auditing tool로, cloud environment의 security posture assessment를 가능하게 합니다.
```bash
virtualenv -p python3 venv
source venv/bin/activate
@@ -404,18 +406,26 @@ python scout.py azure --cli
```
### [Azure-MG-Sub-Governance-Reporting](https://github.com/JulianHayward/Azure-MG-Sub-Governance-Reporting)
이것은 powershell 스크립트로, **Management Group Entra ID 테넌트 내부의 모든 리소스와 권한을 시각화**하고 보안 구성 오류를 찾아줍니다.
이것은 **Management Group Entra ID** tenant 내부의 모든 resource와 permission을 시각화하고 security misconfiguration을 찾는 데 도움이 되는 powershell script입니다.
Az PowerShell module을 사용하여 작동하므로 이 도구에서 지원하는 모든 인증 방식이 그대로 사용 가능합니다.
이 tool은 Az PowerShell module을 사용하므로,tool이 지원하는 모든 authentication이 지원됩니다.
```bash
import-module Az
.\AzGovVizParallel.ps1 -ManagementGroupId <management-group-id> [-SubscriptionIdWhitelist <subscription-id>]
```
## 자동화된 Post-Exploitation 도구
## Automated Post-Exploitation tools
### [**ROADRecon**](https://github.com/dirkjanm/ROADtools)
### [**ROADtools**](https://github.com/dirkjanm/ROADtools) / ROADrecon / ROADtx
ROADRecon의 enumeration은 Entra ID의 구성(예: users, groups, roles, conditional access policies)에 대한 정보를 제공합니다...
ROADtools는 Entra ID offensive research를 위한 주요 오픈소스 framework 중 하나이다. 가장 관련 있는 구성 요소는 다음과 같다:
- **`roadrecon`**: tenant discovery와 로컬 dataset 생성(users, groups, roles, devices, service principals, applications, directory settings).
- **`roadtx`**: token acquisition/exchange, refresh-token reuse, device registration, 그리고 PRT workflows.
- **`roadlib`**: 다른 module들이 사용하는 더 낮은 수준의 auth/API library.
수집된 data는 로컬 SQLite database에 저장되며 ROADrecon web UI에서 탐색할 수 있다. 이는 persistence나 lateral movement를 계획하기 전에 privileged users, role assignments, devices, service principals, 그리고 application relationships를 매핑하는 데 유용하다.
#### ROADrecon collection
```bash
cd ROADTools
pipenv shell
@@ -426,23 +436,56 @@ roadrecon auth --as-app --client "<client-id>" --password "<secret>" --tenant "<
roadrecon gather
roadrecon gui
```
ROADrecon은 원래 Azure AD Graph를 대상으로 했습니다. **2026년 5월 22일** 기준으로, 공식 저장소는 여전히 **`msgraph`** 브랜치에 Microsoft Graph 지원을 유지하고 있으며, **Tom2Byrne/ROADtools** 같은 community fork는 Graph 기반 collection을 계속 업데이트하고 있습니다. Graph를 지원하는 빌드에서는 ROADrecon이 **`-mg`** 스위치를 추가하여 **`/users`**, **`/groups`**, **`/devices`**, **`/servicePrincipals`**, **`/applications`** 같은 endpoints를 enumerate 합니다.
```bash
# Graph-capable ROADrecon builds
roadrecon auth -u test@corp.onmicrosoft.com -p "Welcome2022!"
roadrecon gather -mg
roadrecon gui
```
#### ROADtx high-value use cases
이미 유효한 credentials, refresh token, 또는 PRT-derived session이 있다면, ROADtx는 일반적으로 다음 용도로 사용됩니다:
- **악성 Entra ID device 등록**을 **`urn:ms-drs:enterpriseregistration.windows.net`**에 대해 수행하여 device keys/certificates를 얻고 지속적인 device-backed access를 생성합니다.
- **refresh tokens 교환/재사용**을 통해 인터랙티브 sign-in을 반복하지 않고도 새로운 Microsoft Graph 또는 다른 resource tokens를 얻습니다.
- **PRT workflows 악용**을 통해 백그라운드에서 새 access tokens를 조용히 발급합니다.
유용한 hunting 단서는 기본 **`roadtx device`** 값이 역사적으로 다음과 같았다는 점입니다:
- **OS**: `Windows`
- **OS version**: `10.0.19041.928`
- **Name**: `DESKTOP-<RANDOM 8 DIGITS>`
이 값들은 쉽게 변경할 수 있으므로 **약한 indicator**로 취급해야 합니다. 그럼에도 불구하고, 비정상적인 device registration 이벤트, 비기업식 naming pattern, 의심스러운 source IPs/geos/ASNs, 또는 scripted user agents와 연관될 때는 여전히 유용합니다.
#### ROADtools opsec / hunting notes
ROADtools는 합법적인 Microsoft identity APIs를 사용하므로, defenders는 malware-like signatures를 기대하기보다 token activity, enumeration patterns, user-agent anomalies의 **조합**을 hunting해야 합니다. 유용한 신호는 다음과 같습니다:
- `Add device`, `Add registered owner to device`, `Add registered user to device`, `Register device` 같은 **Device registration** audit operations
- **Device Registration Service**와 연결된 requests 또는 sign-ins
- **`python-requests`**, **`urllib`**, 또는 **`curl`** 같은 script-like user agents
- **`/users`**, **/groups**, **`/devices`**, **`/servicePrincipals`**, 그리고 **`/applications`** 같은 discovery-heavy endpoints에 대한 bursty Microsoft Graph reads
- audit data에 나타나는 강력한 OAuth scopes, 특히 **`Directory.ReadWrite.All`**, **`Device.ReadWrite.All`**, **`Application.ReadWrite.All`**, **`AuditLog.ReadWrite.All`**, 그리고 **`Policy.ReadWrite.All`**
### [**AzureHound**](https://github.com/BloodHoundAD/AzureHound)
AzureHound는 Microsoft Entra ID와 Azure BloodHound 수집기입니다. Windows/Linux/macOS용 단일 정적 Go 바이너리로, 다음 직접 통신합니다:
- Microsoft Graph (Entra ID directory, M365) and
AzureHound는 Microsoft Entra ID와 Azure를 위한 BloodHound collector입니다. Windows/Linux/macOS용 단일 static Go binary이며 다음 직접 연결합니다:
- Microsoft Graph (Entra ID directory, M365) 그리고
- Azure Resource Manager (ARM) control plane (subscriptions, resource groups, compute, storage, key vault, app services, AKS, etc.)
Key traits
- 퍼블릭 인터넷 어디에서나 테넌트 API를 대상으로 실행 (내부 네트워크 접근 불필요)
- 아이덴티티와 클라우드 리소스 전반의 공격 경로를 시각화하기 위해 BloodHound CE가 수집할 수 있는 JSON을 출력
- 관찰된 기본 User-Agent: azurehound/v2.x.x
주요 특징
- public internet의 어디서든 tenant APIs를 대상으로 실행 가능함 (내부 network access 불필요)
- BloodHound CE ingestion을 위한 JSON을 출력하여 identities와 cloud resources 전반의 attack paths를 시각화
- 기본으로 관찰되는 User-Agent: azurehound/v2.x.x
Authentication options
- 사용자 이름 + 비밀번호: -u <upn> -p <password>
- 리프레시 토큰: --refresh-token <rt>
Authentication 옵션
- Username + password: -u <upn> -p <password>
- Refresh token: --refresh-token <rt>
- JSON Web Token (access token): --jwt <jwt>
- 서비스 프린시펄 시크릿: -a <appId> -s <secret>
- 서비스 프린시펄 인증서: -a <appId> --cert <cert.pem> --key <key.pem> [--keypass <pass>]
- Service principal secret: -a <appId> -s <secret>
- Service principal certificate: -a <appId> --cert <cert.pem> --key <key.pem> [--keypass <pass>]
Examples
```bash
@@ -479,37 +522,37 @@ azurehound list storage-containers -t "<tenant-id>" -o containers.json
azurehound list web-apps -t "<tenant-id>" -o webapps.json
azurehound list function-apps -t "<tenant-id>" -o funcapps.json
```
쿼리 대상
무엇이 queried되는지
- Graph endpoints (예시):
- /v1.0/organization, /v1.0/users, /v1.0/groups, /v1.0/roleManagement/directory/roleDefinitions, directoryRoles, owners/members
- ARM endpoints (예시):
- management.azure.com/subscriptions/.../providers/Microsoft.Storage/storageAccounts
- .../Microsoft.KeyVault/vaults, .../Microsoft.Compute/virtualMachines, .../Microsoft.Web/sites, .../Microsoft.ContainerService/managedClusters
사전 검사(preflight) 동작 및 엔드포인트
- 각 azurehound list <object>는 일반적으로 열거 전에 다음 테스트 호출을 수행합니다:
1) Identity 플랫폼: login.microsoftonline.com
Preflight behavior and endpoints
- 각 azurehound list <object>는 보통 enumeration 전에 다음 test calls를 수행합니다:
1) Identity platform: login.microsoftonline.com
2) Graph: GET https://graph.microsoft.com/v1.0/organization
3) ARM: GET https://management.azure.com/subscriptions?api-version=...
- Cloud 환경의 기본 URL Government/China/Germany에 따라 다릅니다. 레포의 constants/environments.go를 참조하세요.
- Cloud environment base URLs는 Government/China/Germany에 따라 다릅니다. repo의 constants/environments.go를 참조하세요.
ARM-중심 객체 (Activity/Resource logs에서 덜 보임)
- 다음 대상 목록은 주로 ARM control plane 읽기 작업을 사용합니다: automation-accounts, container-registries, function-apps, key-vaults, logic-apps, managed-clusters, management-groups, resource-groups, storage-accounts, storage-containers, virtual-machines, vm-scale-sets, web-apps.
- 이러한 GET/list 작업은 일반적으로 Activity Logs에 기록되지 않습니다; 데이터-플레인 읽기(예: *.blob.core.windows.net, *.vault.azure.net)는 리소스 수준의 Diagnostic Settings에 의해 처리됩니다.
ARM-heavy objects (Activity/Resource logs에서 덜 보임)
- 다음 list 대상은 주로 ARM control plane reads를 사용합니다: automation-accounts, container-registries, function-apps, key-vaults, logic-apps, managed-clusters, management-groups, resource-groups, storage-accounts, storage-containers, virtual-machines, vm-scale-sets, web-apps.
- 이러한 GET/list operations는 보통 Activity Logs에 기록되지 않습니다. data-plane reads(예: *.blob.core.windows.net, *.vault.azure.net)는 resource level의 Diagnostic Settings로 확인됩니다.
OPSEC 및 로깅 관련 주의사항
- Microsoft Graph Activity Logs는 기본적으로 활성화되어 있지 않습니다; Graph 호출의 가시성을 얻으려면 활성화 SIEM으로 내보내세요. 프리플라이트 Graph 호출은 GET /v1.0/organization이며 UA azurehound/v2.x.x 예상됩니다.
- Entra ID non-interactive sign-in 로그는 AzureHound가 사용 identity 플랫폼 인증(login.microsoftonline.com) 기록합니다.
- ARM control-plane read/list 작업은 Activity Logs에 기록되지 않습니다; 리소스에 대한 많은 azurehound list 작업이 Activity Logs에 나타나지 않을 것입니다. 서비스 엔드포인트에 대한 읽기는 오직 데이터-플레인 로깅(예: Diagnostic Settings)을 통해 캡처니다.
- Defender XDR GraphApiAuditEvents(미리보기)는 Graph 호출 및 토큰 식별자를 노출할 수 있으나 UserAgent가 없거나 보존 기간이 제한적일 수 있습니다.
OPSEC and logging notes
- Microsoft Graph Activity Logs는 기본적으로 활성화되어 있지 않습니다. Graph calls의 가시성을 얻으려면 활성화하고 SIEM으로 export하세요. Graph preflight GET /v1.0/organization with UA azurehound/v2.x.x 예상하세요.
- Entra ID non-interactive sign-in logs는 AzureHound가 사용하는 identity platform auth(login.microsoftonline.com) 기록합니다.
- ARM control-plane read/list operations는 Activity Logs에 기록되지 않습니다. resources에 대한 많은 azurehound list operations는 거기에 나타나지 않습니다. data-plane logging(Diagnostic Settings 통해)만 service endpoints에 대한 reads를 캡처니다.
- Defender XDR GraphApiAuditEvents(preview)는 Graph calls와 token identifiers를 노출할 수 있지만 UserAgent가 없을 수 있고 retention이 제한적일 수 있습니다.
팁: 권한 경로를 열거할 때는 사용자, 그룹, 역할 및 역할 할당을 덤프한 다음 BloodHound에 로드하고, 사전 구성된 cypher 쿼리를 사용해 Global Administrator/Privileged Role Administrator 및 중첩 그룹과 RBAC 할당을 통한 전이적 권한 상승(transitive escalation)을 찾아보세요.
Tip: privilege paths를 위해 enumeration할 때는 users, groups, roles, role assignments를 dump한 뒤 BloodHound에 ingest하고 prebuilt cypher queries를 사용해 Global Administrator/Privileged Role Administrator 및 nested groups와 RBAC assignments를 통한 transitive escalation을 찾아보세요.
BloodHound 웹을 `curl -L https://ghst.ly/getbhce | docker compose -f - up` 명령으로 실행한 후 `output.json` 파일을 가져오세요. 그런 다음 EXPLORE 의 CYPHER 섹션에서 사전 구성된 쿼리를 포함한 폴더 아이콘을 볼 수 있습니다.
`curl -L https://ghst.ly/getbhce | docker compose -f - up`으로 BloodHound web을 실행하고 `output.json` 파일을 import하세요. 그런 다음 EXPLORE tab의 CYPHER section에서 pre-built queries가 들어 있는 folder icon을 볼 수 있습니다.
### [**MicroBurst**](https://github.com/NetSPI/MicroBurst)
MicroBurst는 Azure Services discovery, weak configuration auditing, 그리고 credential dumping 같은 post exploitation 작업을 지원하는 함수와 스크립트를 포함합니다. 이는 Azure 사용는 penetration tests 중에 사용도록 설계되었습니다.
MicroBurst는 Azure Services discovery, weak configuration auditing, 그리고 credential dumping 같은 post exploitation actions를 지원하는 functions와 scripts를 포함합니다. Azure 사용는 penetration tests 동안 사용도록 의도되었습니다.
```bash
Import-Module .\MicroBurst.psm1
Import-Module .\Get-AzureDomainInfo.ps1
@@ -517,9 +560,9 @@ Get-AzureDomainInfo -folder MicroBurst -Verbose
```
### [**PowerZure**](https://github.com/hausec/PowerZure)
PowerZure는 Azure, EntraID 및 관련 리소스에 대 reconnaissance exploitation을 모두 수행할 수 있는 프레임워크의 필요성에 만들어졌습니다.
PowerZure는 Azure, EntraID 및 관련 리소스에 대 reconnaissance exploitation을 모두 수행할 수 있는 framework의 필요성 때문에 만들어졌다.
이 도구는 **Az PowerShell** 모듈을 사용하므로, 이 모듈이 지원하는 모든 인증 방식이 이 도구에서도 지원됩니다.
이 도구는 **Az PowerShell** module을 사용하므로, 이 도구가 지원하는 모든 authentication 방식이 지원된다.
```bash
# Login
Import-Module Az
@@ -550,7 +593,7 @@ Invoke-AzureRunCommand -Command <command> -VMName <vmname>
```
### [**GraphRunner**](https://github.com/dafthack/GraphRunner/wiki/Invoke%E2%80%90GraphRunner)
GraphRunner Microsoft Graph API와 상호작용하기 위한 post-exploitation 툴셋입니다. Microsoft Entra ID (Azure AD) 계정에서 reconnaissance, persistence pillaging of data를 수행하기 위한 다양한 도구를 제공합니다.
GraphRunner Microsoft Graph API와 상호작용하기 위한 post-exploitation 툴셋입니다. Microsoft Entra ID (Azure AD) 계정에서 reconnaissance, persistence, 그리고 데이터 pillaging 수행하기 위한 다양한 도구를 제공합니다.
```bash
#A good place to start is to authenticate with the Get-GraphTokens module. This module will launch a device-code login, allowing you to authenticate the session from a browser session. Access and refresh tokens will be written to the global $tokens variable. To use them with other GraphRunner modules use the Tokens flag (Example. Invoke-DumpApps -Tokens $tokens)
Import-Module .\GraphRunner.ps1
@@ -594,9 +637,9 @@ Invoke-GraphRunner -Tokens $tokens
```
### [Stormspotter](https://github.com/Azure/Stormspotter)
Stormspotter는 Azure 구독의 리소스에 대한 “attack graph”를 생성합니다. 이 red teams와 pentesters tenant 내에서 attack surface와 pivot 기회를 시각화할 수 있게 해주며, defenders incident response 작업을 빠르게 파악하고 우선순위를 정하는 데 큰 도움이 됩니다.
Stormspotter는 Azure subscription의 리소스 “attack graph”를 생성합니다. 이를 통해 red teams와 pentesters tenant 내 attack surface와 pivot opportunities를 시각화할 수 있, defenders incident response 작업의 방향을 빠르게 고 우선순위를 정하는 데 큰 도움을 받을 수 있습니다.
**안타깝게도, 유지보수가 이루어지지 않는 것으로 보입니다.**
**Unfortunately, it looks unmantained**.
```bash
# Start Backend
cd stormspotter\backend\
@@ -614,11 +657,15 @@ az login -u test@corp.onmicrosoft.com -p Welcome2022!
python stormspotter\stormcollector\sscollector.pyz cli
# This will generate a .zip file to upload in the frontend (127.0.0.1:9091)
```
## 참고자료
- [AzureHound을 이용한 클라우드 발견 (Unit 42)](https://unit42.paloaltonetworks.com/threat-actor-misuse-of-azurehound/)
- [AzureHound 저장소](https://github.com/SpecterOps/AzureHound)
- [BloodHound 저장소](https://github.com/SpecterOps/BloodHound)
- [AzureHound Community Edition 플래그](https://bloodhound.specterops.io/collect-data/ce-collection/azurehound-flags)
## References
- [Cloud Discovery With AzureHound (Unit 42)](https://unit42.paloaltonetworks.com/threat-actor-misuse-of-azurehound/)
- [Paved With Intent: ROADtools and Nation-State Tactics in the Cloud](https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/)
- [ROADtools repository](https://github.com/dirkjanm/ROADtools)
- [ROADtools msgraph branch](https://github.com/dirkjanm/ROADtools/tree/msgraph)
- [Tom2Byrne/ROADtools](https://github.com/Tom2Byrne/ROADtools)
- [AzureHound repository](https://github.com/SpecterOps/AzureHound)
- [BloodHound repository](https://github.com/SpecterOps/BloodHound)
- [AzureHound Community Edition Flags](https://bloodhound.specterops.io/collect-data/ce-collection/azurehound-flags)
- [AzureHound constants/environments.go](https://github.com/SpecterOps/AzureHound/blob/main/constants/environments.go)
- [AzureHound client/storage_accounts.go](https://github.com/SpecterOps/AzureHound/blob/main/client/storage_accounts.go)
- [AzureHound client/roles.go](https://github.com/SpecterOps/AzureHound/blob/main/client/roles.go)