📘
DFIR
Ctrlk
  • Networking
    • Networking
  • Windows
    • Administration
    • Forensics
    • Cheat Sheet
    • Investigation
    • Internals
    • Active Directory
    • MISC
  • Linux
    • Forensics
    • SSH
    • Linux WebShells
    • Directories of Interest
    • Internals
  • Enterprise Architecture
    • CI/CD Pipline
    • Citrix
    • Web Applications
    • The Cloud
      • AWS
      • Azure
        • Hunting
        • Admin
        • Securing Azure
        • CheatSheet
        • Detections
        • Forensics
        • Attacking Azure
          • Initial Access
          • Persistence
            • Cloud VMs
            • Applications
            • SSPR/MFA
            • Automation Account
            • Identity Federation
            • Service Principals
            • Tokens
            • Cross Tenant Synchronization
            • Golden SAML
            • Conditional Access Policies
            • User Creation
          • Credential Theft
          • Execution
          • Exfiltration
          • Test Page
        • Fundementals
        • Logging
      • M365
      • Cloud Labs
    • vSphere
    • Containers
    • Troubleshooting
  • Mac
    • Forensics
  • Attacker Information
    • Adversary Operations
    • Actor Playbooks
    • Abused Domains
  • IR Playbook
    • Activity from Unmanaged Host
    • Recommendations
  • Reverse Engineering
    • Python - Pyinstaller
Powered by GitBook
On this page
  1. Enterprise Architecture
  2. The Cloud
  3. Azure
  4. Attacking Azure

Persistence

LogoOffice365 Attacks: Bypassing MFA, Achieving Persistence and More - Part Iwww.inversecos.com
LogoAttacks on Azure AD and M365: Pawning the cloud, PTA Skeleton Keys and more - PART IIwww.inversecos.com
PreviousM365 Business Email CompromiseNextCloud VMs

Last updated 1 month ago