Runbook 01 — Azure Pentest Methodology
Runbook Information
Section titled “Runbook Information”| Item | Details |
|---|---|
| Runbook ID | GHC-AZ-RB-001 |
| Category | Cloud Penetration Testing |
| Platform | Microsoft Azure |
| Difficulty | Intermediate |
| Estimated Duration | Varies by engagement scope |
| Owner | GoHackersCloud |
| Version | 1.0 |
Purpose
Section titled “Purpose”This runbook provides a structured methodology for conducting authorised Microsoft Azure penetration testing engagements.
It follows the GoHackersCloud Enterprise Cloud Penetration Testing Framework and is designed to ensure every engagement is performed consistently, professionally, and safely.
The methodology can be applied during:
- Internal Security Assessments
- External Penetration Tests
- Cloud Security Reviews
- Azure Configuration Reviews
- Security Consulting Engagements
- Compliance Assessments
- Red Team Preparation
Objectives
Section titled “Objectives”The objectives of an Azure penetration testing engagement are to:
- Identify Azure security weaknesses.
- Validate security controls.
- Assess identity security.
- Review Azure architecture.
- Identify excessive permissions.
- Assess cloud attack surfaces.
- Evaluate monitoring capabilities.
- Measure organisational security posture.
- Produce actionable remediation recommendations.
Typical Azure environments include:
- Microsoft Entra ID
- Azure Subscriptions
- Management Groups
- Resource Groups
- Virtual Networks
- Virtual Machines
- Azure Storage
- Azure SQL
- Azure Kubernetes Service (AKS)
- Azure Functions
- Azure Key Vault
- Azure Monitor
- Microsoft Defender for Cloud
- Microsoft Sentinel
Rules of Engagement
Section titled “Rules of Engagement”Before starting any engagement:
- Obtain written customer approval.
- Confirm engagement scope.
- Review Rules of Engagement.
- Define testing windows.
- Identify restricted systems.
- Confirm emergency contacts.
- Establish evidence handling procedures.
- Agree reporting format.
- Ensure backups exist where appropriate.
- Avoid destructive testing.
Azure Penetration Testing Lifecycle
Section titled “Azure Penetration Testing Lifecycle”The GoHackersCloud methodology consists of nine phases.
Planning
↓
Reconnaissance
↓
Enumeration
↓
Security Assessment
↓
Validation
↓
Risk Analysis
↓
Reporting
↓
Remediation Review
↓
Lessons LearnedPhase 1 — Planning
Section titled “Phase 1 — Planning”Activities
Section titled “Activities”- Review customer objectives.
- Confirm assessment scope.
- Review Azure architecture.
- Identify critical business assets.
- Define engagement success criteria.
- Review previous assessments.
- Prepare documentation templates.
Deliverables
Section titled “Deliverables”- Engagement Plan
- Scope Document
- Rules of Engagement
- Assessment Checklist
Phase 2 — Reconnaissance
Section titled “Phase 2 — Reconnaissance”Objective
Section titled “Objective”Understand the Azure environment before beginning detailed assessments.
Review
Section titled “Review”- Azure subscriptions
- Management Groups
- Resource Groups
- Azure Regions
- Public services
- Internet-facing resources
- Azure DNS configuration
Evidence
Section titled “Evidence”Collect:
- Resource inventory
- Architecture diagrams
- Subscription information
- Initial observations
Phase 3 — Enumeration
Section titled “Phase 3 — Enumeration”Review the following areas.
Identity
Section titled “Identity”- Microsoft Entra ID
- Users
- Groups
- Administrative Roles
- Managed Identities
- Service Principals
Infrastructure
Section titled “Infrastructure”- Virtual Networks
- Virtual Machines
- Storage Accounts
- Azure SQL
- Key Vault
- Azure Functions
- AKS
Governance
Section titled “Governance”- Azure Policy
- Resource Locks
- RBAC
- Tags
- Management Groups
Phase 4 — Security Assessment
Section titled “Phase 4 — Security Assessment”Review implementation of security controls.
Identity Security
Section titled “Identity Security”- MFA
- Conditional Access
- Administrative Roles
- Least Privilege
- Privileged Identity Management
Network Security
Section titled “Network Security”- Network Security Groups
- Azure Firewall
- Public IP exposure
- Private Endpoints
- Bastion
Compute Security
Section titled “Compute Security”- Virtual Machines
- Operating System Hardening
- Defender for Cloud recommendations
- Endpoint Protection
- Patch Management
Storage Security
Section titled “Storage Security”- Public Access
- Encryption
- Access Policies
- SAS Tokens
- Backup Configuration
Secrets Management
Section titled “Secrets Management”Review:
- Azure Key Vault
- Secret Management
- Certificates
- Keys
- Managed Identity usage
Monitoring
Section titled “Monitoring”Review:
- Azure Monitor
- Activity Logs
- Diagnostic Logs
- Microsoft Sentinel
- Defender for Cloud
- Alert Rules
Phase 5 — Validation
Section titled “Phase 5 — Validation”Validate observations safely.
Examples include:
- Confirming excessive permissions.
- Verifying public resource exposure.
- Confirming missing security controls.
- Reviewing configuration weaknesses.
- Validating identity security.
All validation activities must remain within the authorised scope and avoid disruption to production services.
Phase 6 — Risk Analysis
Section titled “Phase 6 — Risk Analysis”Each finding should include:
- Finding ID
- Description
- Business Impact
- Technical Impact
- Likelihood
- Risk Rating
- Evidence
- Recommended Remediation
Risk Ratings
- Critical
- High
- Medium
- Low
- Informational
Phase 7 — Reporting
Section titled “Phase 7 — Reporting”Prepare two reports.
Executive Report
Section titled “Executive Report”Include:
- Engagement Summary
- Overall Security Posture
- Business Risks
- Top Findings
- Priority Recommendations
Technical Report
Section titled “Technical Report”For every finding document:
- Finding Title
- Description
- Affected Resources
- Evidence
- Business Impact
- Technical Impact
- Risk Rating
- Remediation
- References
Phase 8 — Remediation Review
Section titled “Phase 8 — Remediation Review”Discuss findings with the customer.
Review:
- High-risk findings
- Immediate actions
- Long-term improvements
- Azure security roadmap
- Architecture recommendations
Phase 9 — Lessons Learned
Section titled “Phase 9 — Lessons Learned”Conduct an internal engagement review.
Discuss:
- Engagement success
- Challenges encountered
- Methodology improvements
- Tool effectiveness
- Documentation quality
- Customer feedback
- Future recommendations
Evidence Collection Checklist
Section titled “Evidence Collection Checklist”Collect evidence for:
- Azure Portal screenshots
- RBAC assignments
- Microsoft Entra ID configuration
- Azure Policy
- NSG configuration
- Storage configuration
- VM configuration
- Key Vault settings
- Activity Logs
- Monitoring dashboards
All evidence should be securely stored and handled according to the agreed engagement requirements.
Deliverables
Section titled “Deliverables”At the conclusion of the engagement provide:
- Executive Report
- Technical Report
- Risk Register
- Evidence Package
- Architecture Review
- Remediation Roadmap
- Presentation Slides
- Final Customer Debrief
Best Practices
Section titled “Best Practices”Always:
- Work within authorised scope.
- Protect customer data.
- Preserve evidence.
- Document every observation.
- Maintain professional communication.
- Follow responsible disclosure practices.
- Prioritise business risk over technical complexity.
- Provide clear and practical remediation guidance.
Success Criteria
Section titled “Success Criteria”The engagement is considered successful when:
- The agreed scope has been fully assessed.
- Security findings are supported by evidence.
- Risks are prioritised.
- Reports are complete and professional.
- Remediation guidance is actionable.
- Customer objectives have been achieved.
Related Lessons
Section titled “Related Lessons”- Lesson 01 — Azure Offensive Security Foundations
- Lesson 02 — Microsoft Azure Architecture
- Lesson 03 — Microsoft Entra ID Attacks
- Lesson 04 — Azure RBAC Exploitation
- Lesson 09 — Azure Monitoring & Logging
Related Labs
Section titled “Related Labs”- Lab 01 — Microsoft Entra ID Assessment
- Lab 02 — Azure Storage Assessment
- Lab 03 — Azure Virtual Machine Security Assessment
- Lab 04 — Azure Privilege Escalation Assessment
- Lab 05 — Enterprise Azure Cloud Penetration Test
Next Runbook
Section titled “Next Runbook”➡️ Runbook 02 — Azure Identity Assessment
In the next runbook, you will follow a structured enterprise methodology for assessing Microsoft Entra ID, Azure RBAC, Managed Identities, Service Principals, and privileged access configurations during an Azure cloud security engagement.