โ† All cheat sheets

MICROBURST

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

MicroBurst (NetSPI) is a PowerShell toolkit for Azure security testing:
anonymous/unauthenticated enumeration, authenticated recon, credential
and secret hunting, and privilege-escalation helpers across Azure
services. Authorized cloud engagements only.

SETUP#

Import-Module ./MicroBurst.psm1                 # Load the toolkit
# Authenticated modules use the Az / AzureAD PowerShell modules:
Connect-AzAccount                                # Az context
Connect-AzureAD                                  # AzureAD context

UNAUTHENTICATED ENUM#

Invoke-EnumerateAzureBlobs -Base <company>      # Guess storage accounts/blobs
Invoke-EnumerateAzureSubDomains -Base <company> # Find Azure service subdomains
# Discovers public blob containers, app services, databases, etc. from
# a company name - no credentials required

AUTHENTICATED RECON#

Get-AzDomainInfo                                 # Broad tenant/sub dump
Get-AzDomainInfo -Subscription <id>             # Scope to a subscription
# Dumps subscriptions, resources, VMs, storage, network, users, etc.
Get-AzPasswords                                  # Hunt secrets across services

SECRET / CREDENTIAL HUNTING#

Get-AzPasswords                                  # Key Vault keys/secrets,
                                                 # automation accounts, ACR,
                                                 # storage keys, app creds
Get-AzKeyVaultKeysREST                            # Key Vault via REST
Get-AzStorageKeysREST                             # Storage account keys
Get-AzACRKeys                                      # Container Registry creds
# Get-AzPasswords is the flagship loot module - runs many extractors

PRIVILEGE ESCALATION / ABUSE#

Invoke-AzVMBulkCMD -Command "whoami"             # Run cmds on VMs you control
Get-AzRunbookContent                              # Automation runbook secrets
# Managed identity + Run Command are common Azure privesc pivots

REST / TOKEN HELPERS#

Get-AzureADIRMBackup ...                          # Various REST helpers
# Many modules call the Azure REST API directly with an acquired token,
# useful when the Az module is restricted

EXAMPLES#

# Unauthenticated footprint of a target's Azure presence
Invoke-EnumerateAzureSubDomains -Base corpbank -Verbose
Invoke-EnumerateAzureBlobs -Base corpbank

# Full authenticated tenant dump scoped to one subscription
Import-Module ./MicroBurst.psm1
Connect-AzAccount
Get-AzDomainInfo -Subscription <sub-id> -folder ./azdump

# Sweep every reachable secret store for credentials
Get-AzPasswords -Verbose

NOTES#

- Split personality: unauth modules (blob/subdomain enum) need no
  creds; the recon/loot modules need a valid Azure context
- Get-AzPasswords is the highest-value module - it pulls Key Vault,
  storage, ACR, automation, and app secrets in one pass
- Complements your ENTRA-ID-ATTACKS sheet (identity plane) with the
  Azure RESOURCE plane (subscriptions, VMs, storage, Key Vault)
- Detection lives in SENTINEL-KQL (AzureActivity, KeyVault logs) -
  mass secret reads and Run Command are the signals
- For LU FS clients this maps to DORA ICT third-party/cloud risk and
  CSSF cloud-outsourcing review
- PowerShell-based - runs from pwsh on Linux/NixOS with Az modules