Reconnaissance: Azure Cloud w/ Kevin Klingbile
ID: e7d6f32a-ba28-53e4-a92b-43afa665e545
STIX ID: report--e7d6f32a-ba28-53e4-a92b-43afa665e545
Feed Name: Black Hills Infosec Blog
### Executive summary: This Black Hills Information Security webcast (Sept 26, 2024) reviews practical reconnaissance and pentesting techniques for Microsoft cloud environments, distinguishing M365 (SaaS/Entra ID) from Azure (infrastructure/subscriptions). Topics include unauthenticated and authenticated recon (DNS, TXT/SPF/MX checks, static Azure storage URLs), discovery tools (CloudEnum, GreyhatWarfare, AadInternals, Azure Hound, Graph Runner, ScoutSuite), username enumeration methods (OneDrive/Teams/Statistically Likely Usernames, CredMaster/Fireprox), password spraying tradeoffs and fingerprints, token generation and exfiltration (FindMeAccess, teamfiltration), MFA and conditional access pitfalls, and defensive recommendations such as situational awareness, enforcing MFA/conditional access, auditing subscriptions, and using developer tenants for practice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
