top of page

Blog


Abusing Azure VMs: When BitLocker Recovery Turns into an Attack Vector
Hello Readers, Today, we are going to discuss about how BitLocker keys backed up in Entra ID can be abused. So, let's buckle-up and enjoy the blog. Table of contents Introduction In enterprise environments, organizational endpoints and servers often contain crucial data. So, to abide by data-at-rest policies, Microsoft introduced a security feature called BitLocker for Windows Operating systems. BitLocker is used to apply the protection of symmetric encryption for both Operat
Hitesh Duseja
43 minutes ago9 min read


Abusing Global ARM API - Publishing User Compromise
Welcome to this deep dive into Azure security. Whether you are a red teamer, cloud security engineer or just curious about how Azure internals work, this blog has something for you. In this blog, we will discuss the concept of Global Azure Resource Manager (ARM) API endpoints and how they can be abused in certain Azure attack scenarios. To demonstrate this, we will walk through a hands-on lab from Altered Security's Red Labs platform (https://redlabs.enterprisesecurity.io/),
Prajwal Pandey
Jun 199 min read


Reading and Decrypting Key Vault with Runbook MI
We have recently added a new set of 15 Automation Account challenges, each designed to highlight distinct attack vectors and provide comprehensive, hands-on learning opportunities. In this blog post, we will explore one of these Automation Account challenges on the RedLabs platform: Automation Account 13. You can find the complete series of Automation Account challenges on RedLabs platform here: https://redlabs.enterprisesecurity.io/ Before diving into the challenge itself, i
Vishal Raj
Jun 167 min read
bottom of page

