Discover the Unseen: Azure Vulnerability Exploitation

Scott Miller

BSides NYC 2024 · Day 1 · Tech - Red

In his BSides NYC talk, "Discover the Unseen: Azure Vulnerability Exploitation," Scott Miller, a seasoned pentester at Accenture, provided a deep dive into common misconfigurations and attack paths within Microsoft Azure environments. The presentation aimed to inspire offensive security professionals to explore cloud hacking and to encourage general security enthusiasts to delve into the world of penetration testing. Miller meticulously demonstrated how an attacker, starting with initial access, could escalate privileges and exfiltrate sensitive data by exploiting frequently overlooked configuration flaws rather than zero-day vulnerabilities.

AI review

Competent, well-structured intro to Azure attack chaining that covers the greatest hits — blob storage key exposure, over-privileged managed identities, App Admin service principal abuse, and User-Agent CAP bypass. Nothing here is novel; this is well-documented territory, but Miller delivers it cleanly with live demos and a coherent kill chain that makes it genuinely useful for people new to cloud offensive work.

Watch on YouTube