logo

Moving Laterally through Abuse of Managed Identities attached to VMs

ID: f960ccc8-93bf-52f5-a6d8-ced7a3838316

STIX ID: report--f960ccc8-93bf-52f5-a6d8-ced7a3838316

Feed Name: Abstract Security Blog

Date Published: 2026-02-10

Date Updated: 2026-04-26

...
...

This report demonstrates how attackers can abuse Azure Managed Identities to laterally move from a compromised VM to other Azure resources and Key Vault by obtaining tokens from the Instance Metadata Service, bypassing traditional network controls through control-plane command execution. It outlines the attack sequence (initial VM access, MI token harvesting, cross-RG VM command execution, Key Vault access) and provides concrete detection approaches using AzureActivity and AADManagedIdentitySignInLogs, including correlating Managed Identity service principals, inspecting xms_mirid claims, and flagging ImdsIdentityProvider user agents to identify suspicious cross-resource MI activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.