Skip to content

18. Cloud Post-Exploitation

18.1 Azure/Entra ID Attack Paths

  • Gain Global Admin → reset service administrator passwords → access all subscriptions
  • Conditional Access Policy bypass (IP trust / device trust)
  • Managed Identity abuse → access Azure Key Vault/Storage
  • Azure AD Connect sync account → DC Sync
  • Tools: ROADtools / AADInternals

18.2 AWS Post-Exploitation

  • EC2 Instance Metadata → IAM credential theft → AWS CLI lateral movement
  • S3 Bucket enumeration / data theft
  • Lambda function injection / modification
  • CloudTrail log tampering / evasion
  • Tools: Pacu / CloudSploit / ScoutSuite

18.3 M365 Exploitation

  • Exchange Online: OAuth app abuse / mail-rule backdoors
  • SharePoint/OneDrive: file theft / privilege escalation
  • Teams: message phishing / file-sharing abuse
  • Tools: MicroBurst / o365recon