logo

Keeping a Short Leash: New AzureHound Least-Privilege Documentation

ID: 89fcb9d0-d9ca-5436-94e8-a8a7e7a6ecd1

STIX ID: report--89fcb9d0-d9ca-5436-94e8-a8a7e7a6ecd1

Feed Name: SpecterOps Blog

Date Published: 2026-06-08

Date Updated: 2026-06-09

...
...

This SpecterOps research post documents a validated least-privilege permission set for AzureHound by inventorying MS Graph and ARM API calls, mapping them to the narrowest application and RBAC permissions, empirically testing endpoint access and data completeness (permission matrix and full-collection comparisons), and producing updated documentation, scripts, and a custom AzureHound Reader role; the output is defensive guidance to reduce standing access rather than an incident report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.