Skip to content
Breaching Azure+ Advanced
Before You Start
Introduction
Expand
Introduction
4 Topics
Lab Objectives
How to access the Labs
Offensive Azure Security Expert (OASE) Exam
Support
Rules of Engagement
Expand
Rules of Engagement
1 Topic
Command & Control
Breaching Azure Advanced
BAA 00 – Introduction to Azure
Expand
BAA 00 – Introduction to Azure
8 Topics
Microsoft Entra ID
Deprecated Azure Active Directory Graph & Microsoft Graph
Delegated Permissions vs App Registration API Permissions
Managed Identity Vs User Identity
Administrative Units
Azure Lighthouse
Azure Policy
Azure Cloud Shell
BAA 01 – Subdomain Takeover, Teams Phishing & ConsentFix Attack
Expand
BAA 01 – Subdomain Takeover, Teams Phishing & ConsentFix Attack
6 Topics
Subdomain Takeover
Microsoft Teams Phishing
ConsentFix Attack
BAA 01 – Lab
BAA 01 – Lab Solution
BAA 01 – Video Lesson
BAA 02 – Azure VM Metadata Enumeration
Expand
BAA 02 – Azure VM Metadata Enumeration
3 Topics
BAA 02 – Lab
BAA 02 – Lab Solution
BAA 02 – Video Lesson
BAA 03 – Key Vault Access Policies and Secrets
Expand
BAA 03 – Key Vault Access Policies and Secrets
3 Topics
BAA 03 – Lab
BAA 03 – Lab Solution
BAA 03 – Video Lesson
BAA 04 – CosmosDB Data Decryption Utilizing Key Vault Key & Function App
Expand
BAA 04 – CosmosDB Data Decryption Utilizing Key Vault Key & Function App
3 Topics
BAA 04 – Lab
BAA 04 – Lab Solution
BAA 04 – Video Lesson
BAA 05 – Entra ID User Creation by Utilizing Azure Function App
Expand
BAA 05 – Entra ID User Creation by Utilizing Azure Function App
3 Topics
BAA 05 – Lab
BAA 05 – Lab Solution
BAA 05 – Video Lesson
BAA 06 – Entra ID Enumeration
Sample Lesson
Collapse
BAA 06 – Entra ID Enumeration
3 Topics
BAA 06 – Lab
BAA 06 – Lab Solution
BAA 06 – Video Lesson
BAA 07 – Getting RCE on an AzureArc Machine
Expand
BAA 07 – Getting RCE on an AzureArc Machine
3 Topics
BAA 07 – Lab
BAA 07 – Lab Solution
BAA 07 – Video Lesson
BAA 08 – RCE on AKS Through Custom Azure Container Registry Image
Expand
BAA 08 – RCE on AKS Through Custom Azure Container Registry Image
3 Topics
BAA 08 – Lab
BAA 08 – Lab Solution
BAA 08 – Video Lesson
BAA 09 – Compromising an Entra ID Joined Device
Expand
BAA 09 – Compromising an Entra ID Joined Device
3 Topics
BAA 09 – Lab
BAA 09 – Lab Solution
BAA 09 – Video Lesson
BAA 10 – Exporting PRT and Privilege Escalation via PIM
Expand
BAA 10 – Exporting PRT and Privilege Escalation via PIM
3 Topics
BAA 10 – Lab
BAA 10 – Lab Solution
BAA 10 – Video Lesson
BAA 11 – Getting RCE on a Self-Hosted DevOps Agent
Expand
BAA 11 – Getting RCE on a Self-Hosted DevOps Agent
3 Topics
BAA 11 – Lab
BAA 11 – Lab Solution
BAA 11 – Video Lesson
BAA 12 – ADFS Exploitation
Expand
BAA 12 – ADFS Exploitation
3 Topics
BAA 12 – Lab
BAA 12 – Lab Solution
BAA 12 – Video Lesson
BAA 13 – Extracting an Access Token from Browser
Expand
BAA 13 – Extracting an Access Token from Browser
3 Topics
BAA 13 – Lab
BAA 13 – Lab Solution
BAA 13 – Video Lesson
BAA 14 – Exploiting JWT Assertions
Expand
BAA 14 – Exploiting JWT Assertions
3 Topics
BAA 14 – Lab
BAA 14 – Lab Solution
BAA 14 – Video Lesson
BAA 15 – Private Endpoints & ARM Template Data Exposure
Expand
BAA 15 – Private Endpoints & ARM Template Data Exposure
3 Topics
BAA 15 – Lab
BAA 15 – Lab Solution
BAA 15 – Video Lesson
BAA 16 – Device Registration via ADFS Certificate
Expand
BAA 16 – Device Registration via ADFS Certificate
3 Topics
BAA 16 – Lab
BAA 16 – Lab Solution
BAA 16 – Video Lesson
BAA 17 – Exploit Misconfigured Anonymous Azure Storage
Expand
BAA 17 – Exploit Misconfigured Anonymous Azure Storage
2 Topics
BAA 17 – Lab
BAA 17 – Lab Solution
BAA 17 – Final Flag
Previous Topic
Next Lesson
Enter
Presenter Mode
Exit
Presenter Mode
BAA 06 – Video Lesson
Breaching Azure+ Advanced
BAA 06 – Entra ID Enumeration
BAA 06 – Video Lesson
Previous Topic
Back to Lesson
Next Lesson