Keeping a Short Leash: New AzureHound Least-Privilege Documentation
ID: 89fcb9d0-d9ca-5436-94e8-a8a7e7a6ecd1
STIX ID: report--89fcb9d0-d9ca-5436-94e8-a8a7e7a6ecd1
Feed Name: SpecterOps Blog
This SpecterOps research post documents a validated least-privilege permission set for AzureHound by inventorying MS Graph and ARM API calls, mapping them to the narrowest application and RBAC permissions, empirically testing endpoint access and data completeness (permission matrix and full-collection comparisons), and producing updated documentation, scripts, and a custom AzureHound Reader role; the output is defensive guidance to reduce standing access rather than an incident report.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
