Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@ aws elasticache modify-user --user-id default \

</details>

{{#include ../../../../banners/hacktricks-training.md}}


### `elasticache:CreateUser`, `elasticache:CreateUserGroup` | `elasticache:ModifyUserGroup` β€” plant a full-access RBAC user

Expand Down Expand Up @@ -102,3 +102,4 @@ For an **existing** group, `ModifyUserGroup` evaluates more than the group ARN.
- [2] [Resource-level permissions - Amazon ElastiCache](https://docs.aws.amazon.com/AmazonElastiCache/latest/dg/IAM.ResourceLevelPermissions.html)
- [3] [Logging ElastiCache API calls with AWS CloudTrail - Amazon ElastiCache](https://docs.aws.amazon.com/AmazonElastiCache/latest/dg/logging-using-cloudtrail.html)
- [4] [CreateUserGroup - Amazon ElastiCache API](https://docs.aws.amazon.com/AmazonElastiCache/latest/APIReference/API_CreateUserGroup.html)
{{#include ../../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
Expand Up @@ -71,3 +71,4 @@ Version 2 allowed read access plus `CreateApplication`, `CreateService`, and `Cr
- [Shareable AWS resources](https://docs.aws.amazon.com/ram/latest/userguide/shareable.html)
- [PutResourcePolicy API](https://docs.aws.amazon.com/migrationhub-refactor-spaces/latest/APIReference/API_PutResourcePolicy.html)
- [How Refactor Spaces works](https://docs.aws.amazon.com/migrationhub-refactor-spaces/latest/userguide/how-it-works.html)
{{#include ../../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
# AWS - Payment Cryptography Enum

{{#include ../../../banners/hacktricks-training.md}}

## Payment Cryptography

AWS Payment Cryptography is a managed hardware-security-module service for payment keys and payment-specific cryptographic operations. It has two API surfaces:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -191,3 +191,4 @@ Refactor Spaces API calls are CloudTrail management events with `eventSource=ref
- [Sharing environments using AWS RAM](https://docs.aws.amazon.com/migrationhub-refactor-spaces/latest/userguide/sharing.html)
- [Actions, resources, and condition keys](https://docs.aws.amazon.com/service-authorization/latest/reference/list_migration-hub-refactor-spaces.html)
- [Logging Refactor Spaces API calls with CloudTrail](https://docs.aws.amazon.com/migrationhub-refactor-spaces/latest/userguide/logging-using-cloudtrail.html)
{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
Expand Up @@ -26,3 +26,4 @@ A `ResourceNotFoundException` can mean no configuration or policy exists. Inspec

1. [AWS Sign-In console access control](https://docs.aws.amazon.com/signin/latest/userguide/console-access-control.html)
2. [AWS Sign-In actions and permissions](https://docs.aws.amazon.com/service-authorization/latest/reference/list_signin.html)
{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
# AWS - Supply Chain Enum

{{#include ../../../banners/hacktricks-training.md}}

## AWS Supply Chain

AWS Supply Chain (`scn`) provides a regional, Identity Center-backed web application and a SigV4 API for instances, data-lake schemas, ingestion events, SQL transformation flows and bill-of-materials imports. An instance can contain commercially sensitive inventory, forecasts, orders, shipments, supplier and manufacturing data.
Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
# AWS permissions categories

{{#include ../../banners/hacktricks-training.md}}

The canonical [AWS categorization file](../../permission-categorizations/aws.yaml) supplies the permission ratings used by CloudPEASS and Blue-CloudPEASS.

- **Critical**: direct or almost independent privilege escalation, powerful identity grants, or privileged execution.
Expand All @@ -20,3 +22,4 @@ Browse the complete categorization below, [download the YAML](../../permission-c
</div>

<noscript>Enable JavaScript to see the YAML inline, or open the download or GitHub source links above.</noscript>
{{#include ../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
Expand Up @@ -238,7 +238,7 @@ Submit the narrow data-plane request directly. A successful configuration PUT ch

See [Azure AI Search indexers](https://learn.microsoft.com/en-us/azure/search/search-indexer-overview), [connect to Azure Storage with a managed identity](https://learn.microsoft.com/en-us/azure/search/search-how-to-managed-identities), and the [Search Service REST API](https://learn.microsoft.com/en-us/rest/api/searchservice/).

{{#include ../../../banners/hacktricks-training.md}}


<details>
<summary>Logs generated</summary>
Expand All @@ -252,3 +252,4 @@ See [Azure AI Search indexers](https://learn.microsoft.com/en-us/azure/search/se
- The follow-up blind PUT is a data-plane call to `*.search.windows.net` not captured in the Activity Log (only AI Search OperationLogs, off by default); a 403 on a GET does not imply the corresponding blind write is logged or blocked

</details>
{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
Expand Up @@ -243,7 +243,7 @@ $base = "/subscriptions/$subscriptionId/resourceGroups/$resourceGroup/providers/

Refreshing the Azure CLI or PowerShell token may be necessary immediately after a new exact role assignment. Resource responses redact secure environment variables, but plain values, declared outputs, and printed logs must all be reviewed independently.

{{#include ../../../banners/hacktricks-training.md}}


<details>
<summary>Logs generated</summary>
Expand All @@ -257,3 +257,4 @@ Refreshing the Azure CLI or PowerShell token may be necessary immediately after
- NOT recorded: the specific outputs/log content read is never captured centrally; responses redact secure environment variables but plain values, declared outputs, and printed logs are returned to the caller unlogged.

</details>
{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
Expand Up @@ -58,7 +58,7 @@ Use `Owner` (`8e3af657-a8ff-443c-a75c-2fe8c4bcb635`) instead of `Reader` to take

See [Template specs](https://learn.microsoft.com/en-us/azure/azure-resource-manager/templates/template-specs) and [Assign Azure roles using ARM templates](https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-template).

{{#include ../../../banners/hacktricks-training.md}}


<details>
<summary>Logs generated</summary>
Expand All @@ -73,3 +73,4 @@ See [Template specs](https://learn.microsoft.com/en-us/azure/azure-resource-mana
- NOT recorded as the attacker's action: the later victim deployment that executes the payload is logged as the VICTIM's own `Microsoft.Resources/deployments/write` plus the created resources/role assignments under the deployer's identity β€” not attributed to the attacker; the poisoned template body stored in the version is not shown in the Activity Log, and reads of the version's template are GETs that are not logged.

</details>
{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
Expand Up @@ -184,10 +184,11 @@ AzurePEASS marks these permissions high. The key grants trusted-service capabili

</details>

{{#include ../../../banners/hacktricks-training.md}}


## References

- [1] [Azure Communication Services β€” Email domains and sender authentication](https://learn.microsoft.com/en-us/azure/communication-services/concepts/email/email-domain-and-sender-authentication)
- [Azure Communication Services Chat logs](https://learn.microsoft.com/en-us/azure/communication-services/concepts/analytics/logs/chat-logs)
- [Communication Services Azure Monitor tables](https://learn.microsoft.com/en-us/azure/azure-monitor/reference/tables/microsoft-communication-communicationservices)
{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
Expand Up @@ -182,7 +182,7 @@ Databricks protects the workspace's **managed resource group** (DBFS-root storag

See [Databricks cluster init scripts](https://learn.microsoft.com/en-us/azure/databricks/init-scripts/), [global init scripts](https://learn.microsoft.com/en-us/azure/databricks/init-scripts/global), [secret scopes](https://learn.microsoft.com/en-us/azure/databricks/security/secrets/), [Unity Catalog storage credentials](https://learn.microsoft.com/en-us/azure/databricks/connect/unity-catalog/), and [Access Connector for Azure Databricks](https://learn.microsoft.com/en-us/azure/databricks/connect/unity-catalog/storage-credentials).

{{#include ../../../banners/hacktricks-training.md}}


<details>
<summary>Logs generated</summary>
Expand All @@ -209,3 +209,4 @@ See [Databricks cluster init scripts](https://learn.microsoft.com/en-us/azure/da
- The SCIM `admins`-group bootstrap and confirmation calls go to the workspace endpoint `adb-<id>.<shard>.azuredatabricks.net` β€” a data-plane operation NOT in the Azure Activity Log; only Databricks' own workspace audit logs (separate product, off/diagnostic-configured) would record it

</details>
{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
Expand Up @@ -426,7 +426,7 @@ The exact property names and their nesting vary between namespaces, topics, and
> [!NOTE]
> **Cross-tenant partner event injection (`partnerConfigurations/authorizePartner/action`, `partnerConfigurations/write`, `partnerNamespaces/*` β€” preview/niche).** Partner configuration governs which external partners may push events into the tenant. Authorizing an attacker-controlled partner registration/namespace establishes a sanctioned cross-tenant channel to inject events into partner topics that feed victim subscriptions β€” a stealthy, tenant-blessed injection/persistence path that resembles a legitimate partner integration. Requires **EventGrid Contributor**; both ops are control-plane and land in the Activity Log (~90d). Authorization expiry can limit how long a partner remains authorized.

{{#include ../../../banners/hacktricks-training.md}}


<details>
<summary>Logs generated</summary>
Expand All @@ -439,3 +439,4 @@ The exact property names and their nesting vary between namespaces, topics, and
- It appears only in the topic's data-plane diagnostic logs (off by default); the separate namespace/topic/subscription management reads are not required, so no `Administrative` entry records the pull.

</details>
{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
Expand Up @@ -86,7 +86,7 @@ References: [Fluid Relay authentication and authorization](https://learn.microso

</details>

{{#include ../../../banners/hacktricks-training.md}}


<details>
<summary>Logs generated</summary>
Expand All @@ -100,3 +100,4 @@ References: [Fluid Relay authentication and authorization](https://learn.microso
- The subsequent JWT-signed client access to the Fluid service endpoint is **data-plane** and is **not** in the Activity Log.

</details>
{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
Expand Up @@ -473,7 +473,7 @@ See [X.509 CA certificate security with IoT Hub](https://learn.microsoft.com/en-
> [!NOTE]
> **Defense evasion.** `Microsoft.Devices/iotHubs/diagnosticSettings/write` (and `provisioningServices/diagnosticSettings/write`) let an attacker delete or rewire the diagnostic setting that, in a mature target, routes the IoT Hub/DPS data-plane categories (`DeviceIdentityOperations`, `Connections`, `C2DCommands`, `DirectMethods`, `FileUploadOperations`, `Routes`, DPS `DeviceOperations`/`ServiceOperations`) to Log Analytics/Storage/Event Hub β€” blinding exactly the telemetry that would record every data-plane technique on this page. The change is itself a control-plane Activity Log β€” Administrative event (~90d), so disabling logging does not erase the record that logging was changed. `iotHubs/Delete` / `provisioningServices/Delete` are destructive DoS only.

{{#include ../../../banners/hacktricks-training.md}}


<details>
<summary>Logs generated</summary>
Expand All @@ -487,3 +487,4 @@ See [X.509 CA certificate security with IoT Hub](https://learn.microsoft.com/en-
- The DPS `enrollments/read` and `enrollmentGroups/read` actions are DPS data-plane reads over `*.azure-devices-provisioning.net` and are NOT in the Activity Log β€” only in DPS diagnostic logs (off by default); NOT recorded either way: no key material is returned so nothing sensitive is disclosed.

</details>
{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
Expand Up @@ -148,7 +148,7 @@ For persistence techniques, see [Az - Notification Hubs Persistence](../az-persi

- [1] [Notification Hubs - Debug Send (REST API)](https://learn.microsoft.com/en-us/rest/api/notificationhubs/notification-hubs/debug-send)

{{#include ../../../banners/hacktricks-training.md}}


<details>
<summary>Logs generated</summary>
Expand All @@ -161,3 +161,4 @@ For persistence techniques, see [Az - Notification Hubs Persistence](../az-persi
- `.../pnsCredentials/action` is logged in the **Activity Log** (Administrative, ~90 days); the returned credential values are only in the response body, not the log.

</details>
{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@ The jobs response can disclose creator information, targets, status, metadata, c

If resource enumeration is denied, recover the workspace name, region, resource group, and subscription from a returned connection string, application configuration, source, deployment output, or logs. See [authenticate with Azure Quantum access keys](https://learn.microsoft.com/en-us/azure/quantum/security-manage-access-keys), [list workspace keys](https://learn.microsoft.com/en-us/rest/api/azurequantum/resourcemanager/workspaces/list-keys?view=rest-azurequantum-resourcemanager-2025-12-15-preview), [regenerate workspace keys](https://learn.microsoft.com/en-us/rest/api/azurequantum/resourcemanager/workspaces/regenerate-keys?view=rest-azurequantum-resourcemanager-2025-12-15-preview), and [list jobs](https://learn.microsoft.com/en-us/rest/api/azurequantum/dataplane/jobs/list?view=rest-azurequantum-dataplane-2026-01-15-preview).

{{#include ../../../banners/hacktricks-training.md}}


<details>
<summary>Logs generated</summary>
Expand All @@ -57,3 +57,4 @@ If resource enumeration is denied, recover the workspace name, region, resource
- NOT recorded there: the subsequent `x-ms-quantum-api-key`-authenticated data-plane calls to `<workspace>.<region>.quantum.azure.com` (jobs list, etc.) are not in the Activity Log; they appear only in the Quantum workspace's diagnostic logs, off by default.

</details>
{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
Expand Up @@ -251,7 +251,7 @@ It operates on supplied credentials (no job β†’ no job MI at location scope), so
> [!NOTE]
> Stream Analytics has **no** `listKeys`/`listSecrets`/secret-read operation β€” `inputs/Read`/`outputs/Read` mask the account/shared-access key, so there is no service-native connection-secret-extraction technique. Every op is control-plane (no `isDataAction:true` action exists), so all of the above land in the Activity Log Administrative category by default. `streamingjobs/Scale/action` (inflate streaming units = cost DoS) and the various `Delete` ops are availability/DoS only. Diagnostic-setting teardown is done via `Microsoft.Insights/diagnosticSettings/*` (a different provider), not a Stream-Analytics-specific op.

{{#include ../../../banners/hacktricks-training.md}}


<details>
<summary>Logs generated</summary>
Expand All @@ -265,3 +265,4 @@ It operates on supplied credentials (no job β†’ no job MI at location scope), so
- The exfiltrated event records written to the attacker's Storage sink are NOT captured by the Stream Analytics job's Azure Activity Log; the data flow itself appears only in the job's/destination's data-plane diagnostic logs (off by default)

</details>
{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
# Azure permissions categories

{{#include ../../banners/hacktricks-training.md}}

The canonical [Azure categorization file](../../permission-categorizations/azure.yaml) supplies the permission ratings used by CloudPEASS and Blue-CloudPEASS.

- **Critical**: direct or almost independent privilege escalation, powerful identity grants, or privileged execution.
Expand All @@ -20,3 +22,4 @@ Browse the complete categorization below, [download the YAML](../../permission-c
</div>

<noscript>Enable JavaScript to see the YAML inline, or open the download or GitHub source links above.</noscript>
{{#include ../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
Expand Up @@ -190,3 +190,4 @@ The destination owner must attach a subscription before messages can be retained
5. [View Cloud Healthcare API error logs](https://docs.cloud.google.com/healthcare-api/docs/how-tos/logging)
6. [FHIR Pub/Sub notifications](https://docs.cloud.google.com/healthcare-api/docs/fhir-pubsub)
7. [Pub/Sub audit logging](https://docs.cloud.google.com/pubsub/docs/audit-logging)
{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
Expand Up @@ -220,3 +220,4 @@ The explicit `--condition=None` makes this an unconditional binding even when th
18. [Cloud Deploy CustomTargetType PATCH API](https://docs.cloud.google.com/deploy/docs/api/reference/rest/v1/projects.locations.customTargetTypes/patch)
19. [Cloud Run deployment permissions](https://docs.cloud.google.com/run/docs/reference/iam/roles#deployment_permissions)
20. [IAM Policy version and etag contract](https://docs.cloud.google.com/iam/docs/reference/rest/v1/Policy)
{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
Expand Up @@ -265,3 +265,4 @@ gcp-storage-privesc.md
17. [Cloud Storage audit logging](https://docs.cloud.google.com/storage/docs/audit-logging)
18. [Cloud Build audit logging](https://docs.cloud.google.com/build/docs/securing-builds/audit-logs)
19. [Artifact Registry audit logging](https://docs.cloud.google.com/artifact-registry/docs/audit-logging)
{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ resources:
serviceAccounts:
- email: TARGET_PRIVILEGED_SA@PROJECT_ID.iam.gserviceaccount.com
scopes:
- https://www.googleapis.com/auth/cloud-platform
- [https://www.googleapis.com/auth/cloud-platform](https://www.googleapis.com/auth/cloud-platform)
metadata:
items:
- key: startup-script
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -105,3 +105,4 @@ Cloud Healthcare's audit catalog records the generic IAM method names rather tha
1. [Controlling access to Cloud Healthcare API resources](https://docs.cloud.google.com/healthcare-api/docs/controlling-access)
2. [Cloud Healthcare API access control and predefined roles](https://docs.cloud.google.com/healthcare-api/docs/access-control)
3. [Cloud Healthcare API audit logging](https://docs.cloud.google.com/healthcare-api/docs/how-tos/audit-logging)
{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ name: attacker-allow
target:
loadBalancingScheme: EXTERNAL_MANAGED
resources:
- https://www.googleapis.com/compute/v1/projects/PROJECT_ID/global/forwardingRules/VICTIM_RULE
- [https://www.googleapis.com/compute/v1/projects/PROJECT_ID/global/forwardingRules/VICTIM_RULE](https://www.googleapis.com/compute/v1/projects/PROJECT_ID/global/forwardingRules/VICTIM_RULE)
httpRules:
- from:
sources:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -144,3 +144,4 @@ Repeat with `dicom-stores`, `hl7v2-stores`, and `consent-stores` as relevant. Ch
2. [Controlling access to Cloud Healthcare API resources](https://docs.cloud.google.com/healthcare-api/docs/controlling-access)
3. [Cloud Healthcare API audit logging](https://docs.cloud.google.com/healthcare-api/docs/how-tos/audit-logging)
4. [FHIR store REST resource](https://docs.cloud.google.com/healthcare-api/docs/reference/rest/v1/projects.locations.datasets.fhirStores#FhirStore)
{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
Expand Up @@ -68,3 +68,4 @@ The analogous HL7v2 exposure needs `healthcare.hl7V2Messages.get` for a known me
2. [FHIR REST method authorization scopes](https://docs.cloud.google.com/healthcare-api/docs/reference/rest/v1/projects.locations.datasets.fhirStores.fhir/read)
3. [Controlling access to Cloud Healthcare API resources](https://docs.cloud.google.com/healthcare-api/docs/controlling-access)
4. [Cloud Healthcare API audit logging](https://docs.cloud.google.com/healthcare-api/docs/how-tos/audit-logging)
{{#include ../../../banners/hacktricks-training.md}}
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
# GCP permissions categories

{{#include ../../banners/hacktricks-training.md}}

The canonical [GCP categorization file](../../permission-categorizations/gcp.yaml) supplies the permission ratings used by CloudPEASS and Blue-CloudPEASS.

- **Critical**: direct or almost independent privilege escalation, powerful identity grants, or privileged execution.
Expand All @@ -20,3 +22,4 @@ Browse the complete categorization below, [download the YAML](../../permission-c
</div>

<noscript>Enable JavaScript to see the YAML inline, or open the download or GitHub source links above.</noscript>
{{#include ../../banners/hacktricks-training.md}}
Loading
Loading