Pentesting 8
- Azure Pentesting — References, Tools & Cheatsheet
- EntraGoat: Application Ownership Chain and Credential Bypass
- EntraGoat: Dynamic Administrative Unit Poisoning via PIM Group Ownership
- BadZure: Managed Identity Abuse via Function App (Flex Consumption)
- BadZure: Managed Identity Abuse via Logic App
- BadZure: Storage Certificate Theft via Service Principal
- BadZure: Cloud Application Administrator vs Application Administrator
- BadZure: Application Administrator via Group Membership