18. Cloud Post-Exploitation
18.1 Azure/Entra ID Attack Paths
- Gain Global Admin → reset service administrator passwords → access all subscriptions
- Conditional Access Policy bypass (IP trust / device trust)
- Managed Identity abuse → access Azure Key Vault/Storage
- Azure AD Connect sync account → DC Sync
- Tools: ROADtools / AADInternals
18.2 AWS Post-Exploitation
- EC2 Instance Metadata → IAM credential theft → AWS CLI lateral movement
- S3 Bucket enumeration / data theft
- Lambda function injection / modification
- CloudTrail log tampering / evasion
- Tools: Pacu / CloudSploit / ScoutSuite
18.3 M365 Exploitation
- Exchange Online: OAuth app abuse / mail-rule backdoors
- SharePoint/OneDrive: file theft / privilege escalation
- Teams: message phishing / file-sharing abuse
- Tools: MicroBurst / o365recon