Unwelcome Guest: Abusing Azure Guest Access to Dump…
ID: 71d6b604-befb-5855-a0c9-62b8e0643c0b
STIX ID: report--71d6b604-befb-5855-a0c9-62b8e0643c0b
Feed Name: TrustedSec blog
Threat Score
This report demonstrates a reconnaissance technique against Azure AD tenants where a guest account (with default external collaboration settings) can programmatically enumerate users, groups, group memberships, and applications by discovering ObjectIds and using PowerShell and Microsoft Graph calls; the author provides a proof-of-concept script, discusses attack methodology and automation, and recommends restricting guest permissions as remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
