logo

Automating Azure Abuse Research — Part 2

ID: db1aa2c4-bd16-56a2-bd68-94d1cc86c3fd

STIX ID: report--db1aa2c4-bd16-56a2-bd68-94d1cc86c3fd

Feed Name: SpecterOps Blog

Date Published: 2022-08-31

Date Updated: 2026-04-30

Author: Andy Robbins

...
...

This post introduces the BloodHound Attack Research Kit (BARK) and shows how to automate, at scale, the validation of Azure abuse primitives using PowerShell-based atomic tests. It demonstrates testing which Azure RBAC roles allow executing commands on Virtual Machines via the RunCommand endpoint, running tests in parallel, and exporting results for reporting—enabling continuous, evidence-based verification of risky configurations as Azure services and permissions evolve.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.