MICROBURST
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
MicroBurst (NetSPI) is a PowerShell toolkit for Azure security testing: anonymous/unauthenticated enumeration, authenticated recon, credential and secret hunting, and privilege-escalation helpers across Azure services. Authorized cloud engagements only.
SETUP#
Import-Module ./MicroBurst.psm1 # Load the toolkit # Authenticated modules use the Az / AzureAD PowerShell modules: Connect-AzAccount # Az context Connect-AzureAD # AzureAD context
UNAUTHENTICATED ENUM#
Invoke-EnumerateAzureBlobs -Base <company> # Guess storage accounts/blobs Invoke-EnumerateAzureSubDomains -Base <company> # Find Azure service subdomains # Discovers public blob containers, app services, databases, etc. from # a company name - no credentials required
AUTHENTICATED RECON#
Get-AzDomainInfo # Broad tenant/sub dump Get-AzDomainInfo -Subscription <id> # Scope to a subscription # Dumps subscriptions, resources, VMs, storage, network, users, etc. Get-AzPasswords # Hunt secrets across services
SECRET / CREDENTIAL HUNTING#
Get-AzPasswords # Key Vault keys/secrets,
# automation accounts, ACR,
# storage keys, app creds
Get-AzKeyVaultKeysREST # Key Vault via REST
Get-AzStorageKeysREST # Storage account keys
Get-AzACRKeys # Container Registry creds
# Get-AzPasswords is the flagship loot module - runs many extractors
PRIVILEGE ESCALATION / ABUSE#
Invoke-AzVMBulkCMD -Command "whoami" # Run cmds on VMs you control Get-AzRunbookContent # Automation runbook secrets # Managed identity + Run Command are common Azure privesc pivots
REST / TOKEN HELPERS#
Get-AzureADIRMBackup ... # Various REST helpers # Many modules call the Azure REST API directly with an acquired token, # useful when the Az module is restricted
EXAMPLES#
# Unauthenticated footprint of a target's Azure presence Invoke-EnumerateAzureSubDomains -Base corpbank -Verbose Invoke-EnumerateAzureBlobs -Base corpbank # Full authenticated tenant dump scoped to one subscription Import-Module ./MicroBurst.psm1 Connect-AzAccount Get-AzDomainInfo -Subscription <sub-id> -folder ./azdump # Sweep every reachable secret store for credentials Get-AzPasswords -Verbose
NOTES#
- Split personality: unauth modules (blob/subdomain enum) need no creds; the recon/loot modules need a valid Azure context - Get-AzPasswords is the highest-value module - it pulls Key Vault, storage, ACR, automation, and app secrets in one pass - Complements your ENTRA-ID-ATTACKS sheet (identity plane) with the Azure RESOURCE plane (subscriptions, VMs, storage, Key Vault) - Detection lives in SENTINEL-KQL (AzureActivity, KeyVault logs) - mass secret reads and Run Command are the signals - For LU FS clients this maps to DORA ICT third-party/cloud risk and CSSF cloud-outsourcing review - PowerShell-based - runs from pwsh on Linux/NixOS with Az modules