Pandora’s Container Part 1: Unpacking Azure Container Security
ID: f9c649d6-a5a4-5e21-b4e4-4256f309ae00
STIX ID: report--f9c649d6-a5a4-5e21-b4e4-4256f309ae00
Feed Name: TrustedSec blog
This blog post demonstrates practical attack techniques against Azure container services: enumerating ACR roles and credentials, enabling admin access, abusing ACR Tasks and managed identities to fetch Key Vault secrets, creating tokens/scope maps, and replacing container images with malicious Dockerfiles that steal IMDS tokens, exfiltrate secrets to webhooks or ngrok listeners, or establish reverse shells. It includes PoC commands, Dockerfiles, and mitigation recommendations such as enforcing least privilege, resource scoping, and MFA/Conditional Access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
