Skip to content

Runbook 01 — Azure Pentest Methodology

Item Details
Runbook ID GHC-AZ-RB-001
Category Cloud Penetration Testing
Platform Microsoft Azure
Difficulty Intermediate
Estimated Duration Varies by engagement scope
Owner GoHackersCloud
Version 1.0

This runbook provides a structured methodology for conducting authorised Microsoft Azure penetration testing engagements.

It follows the GoHackersCloud Enterprise Cloud Penetration Testing Framework and is designed to ensure every engagement is performed consistently, professionally, and safely.

The methodology can be applied during:

  • Internal Security Assessments
  • External Penetration Tests
  • Cloud Security Reviews
  • Azure Configuration Reviews
  • Security Consulting Engagements
  • Compliance Assessments
  • Red Team Preparation

The objectives of an Azure penetration testing engagement are to:

  • Identify Azure security weaknesses.
  • Validate security controls.
  • Assess identity security.
  • Review Azure architecture.
  • Identify excessive permissions.
  • Assess cloud attack surfaces.
  • Evaluate monitoring capabilities.
  • Measure organisational security posture.
  • Produce actionable remediation recommendations.

Typical Azure environments include:

  • Microsoft Entra ID
  • Azure Subscriptions
  • Management Groups
  • Resource Groups
  • Virtual Networks
  • Virtual Machines
  • Azure Storage
  • Azure SQL
  • Azure Kubernetes Service (AKS)
  • Azure Functions
  • Azure Key Vault
  • Azure Monitor
  • Microsoft Defender for Cloud
  • Microsoft Sentinel

Before starting any engagement:

  • Obtain written customer approval.
  • Confirm engagement scope.
  • Review Rules of Engagement.
  • Define testing windows.
  • Identify restricted systems.
  • Confirm emergency contacts.
  • Establish evidence handling procedures.
  • Agree reporting format.
  • Ensure backups exist where appropriate.
  • Avoid destructive testing.

The GoHackersCloud methodology consists of nine phases.

Planning
Reconnaissance
Enumeration
Security Assessment
Validation
Risk Analysis
Reporting
Remediation Review
Lessons Learned

  • Review customer objectives.
  • Confirm assessment scope.
  • Review Azure architecture.
  • Identify critical business assets.
  • Define engagement success criteria.
  • Review previous assessments.
  • Prepare documentation templates.
  • Engagement Plan
  • Scope Document
  • Rules of Engagement
  • Assessment Checklist

Understand the Azure environment before beginning detailed assessments.

  • Azure subscriptions
  • Management Groups
  • Resource Groups
  • Azure Regions
  • Public services
  • Internet-facing resources
  • Azure DNS configuration

Collect:

  • Resource inventory
  • Architecture diagrams
  • Subscription information
  • Initial observations

Review the following areas.

  • Microsoft Entra ID
  • Users
  • Groups
  • Administrative Roles
  • Managed Identities
  • Service Principals
  • Virtual Networks
  • Virtual Machines
  • Storage Accounts
  • Azure SQL
  • Key Vault
  • Azure Functions
  • AKS
  • Azure Policy
  • Resource Locks
  • RBAC
  • Tags
  • Management Groups

Review implementation of security controls.

  • MFA
  • Conditional Access
  • Administrative Roles
  • Least Privilege
  • Privileged Identity Management

  • Network Security Groups
  • Azure Firewall
  • Public IP exposure
  • Private Endpoints
  • Bastion

  • Virtual Machines
  • Operating System Hardening
  • Defender for Cloud recommendations
  • Endpoint Protection
  • Patch Management

  • Public Access
  • Encryption
  • Access Policies
  • SAS Tokens
  • Backup Configuration

Review:

  • Azure Key Vault
  • Secret Management
  • Certificates
  • Keys
  • Managed Identity usage

Review:

  • Azure Monitor
  • Activity Logs
  • Diagnostic Logs
  • Microsoft Sentinel
  • Defender for Cloud
  • Alert Rules

Validate observations safely.

Examples include:

  • Confirming excessive permissions.
  • Verifying public resource exposure.
  • Confirming missing security controls.
  • Reviewing configuration weaknesses.
  • Validating identity security.

All validation activities must remain within the authorised scope and avoid disruption to production services.


Each finding should include:

  • Finding ID
  • Description
  • Business Impact
  • Technical Impact
  • Likelihood
  • Risk Rating
  • Evidence
  • Recommended Remediation

Risk Ratings

  • Critical
  • High
  • Medium
  • Low
  • Informational

Prepare two reports.

Include:

  • Engagement Summary
  • Overall Security Posture
  • Business Risks
  • Top Findings
  • Priority Recommendations

For every finding document:

  • Finding Title
  • Description
  • Affected Resources
  • Evidence
  • Business Impact
  • Technical Impact
  • Risk Rating
  • Remediation
  • References

Discuss findings with the customer.

Review:

  • High-risk findings
  • Immediate actions
  • Long-term improvements
  • Azure security roadmap
  • Architecture recommendations

Conduct an internal engagement review.

Discuss:

  • Engagement success
  • Challenges encountered
  • Methodology improvements
  • Tool effectiveness
  • Documentation quality
  • Customer feedback
  • Future recommendations

Collect evidence for:

  • Azure Portal screenshots
  • RBAC assignments
  • Microsoft Entra ID configuration
  • Azure Policy
  • NSG configuration
  • Storage configuration
  • VM configuration
  • Key Vault settings
  • Activity Logs
  • Monitoring dashboards

All evidence should be securely stored and handled according to the agreed engagement requirements.


At the conclusion of the engagement provide:

  • Executive Report
  • Technical Report
  • Risk Register
  • Evidence Package
  • Architecture Review
  • Remediation Roadmap
  • Presentation Slides
  • Final Customer Debrief

Always:

  • Work within authorised scope.
  • Protect customer data.
  • Preserve evidence.
  • Document every observation.
  • Maintain professional communication.
  • Follow responsible disclosure practices.
  • Prioritise business risk over technical complexity.
  • Provide clear and practical remediation guidance.

The engagement is considered successful when:

  • The agreed scope has been fully assessed.
  • Security findings are supported by evidence.
  • Risks are prioritised.
  • Reports are complete and professional.
  • Remediation guidance is actionable.
  • Customer objectives have been achieved.

  • Lesson 01 — Azure Offensive Security Foundations
  • Lesson 02 — Microsoft Azure Architecture
  • Lesson 03 — Microsoft Entra ID Attacks
  • Lesson 04 — Azure RBAC Exploitation
  • Lesson 09 — Azure Monitoring & Logging

  • Lab 01 — Microsoft Entra ID Assessment
  • Lab 02 — Azure Storage Assessment
  • Lab 03 — Azure Virtual Machine Security Assessment
  • Lab 04 — Azure Privilege Escalation Assessment
  • Lab 05 — Enterprise Azure Cloud Penetration Test

➡️ Runbook 02 — Azure Identity Assessment

In the next runbook, you will follow a structured enterprise methodology for assessing Microsoft Entra ID, Azure RBAC, Managed Identities, Service Principals, and privileged access configurations during an Azure cloud security engagement.