Course

Azure Hacking Workshop («AZHACK»)

A look at cloud security from both sides, attacker and defender. Understanding how attackers act and think allows you to build a much better defense. Students gain insights that will encourage them to fix misconfigurations in existing infrastructure.
Duration 2 days
Price 2'100.–

Course facts

Key Learnings
  • Finding misconfigurations in a Hybrid Identity infrastructure
  • Configuring identity services to protect them from threats against identities
  • Using Managed Identities securely
  • Configuring virtual machines security to prevent them from being compromised
  • Understanding the functionality of container services in Azure
  • Understanding how containers could be compromised and how they should be deployed securely
  • Finding typical misconfigurations in Azure App Service and Azure SQL
Content

Module 1 – Hybrid Identity Protection
Hybrid Identity that’s what most companies use in their environment. Hybrid Identity gives additional benefits and additional risks. The goal is to mitigate those risks.

  • Pentesting Microsoft Entra Connect Sync and Cloud Sync
  • Secure Microsoft Entra Sync and Cloud Sync configuration
  • Where tokens are stored on the machine
  • Working with leaked credentials
  • Credentials protection

Module 2 – Managed Identity
Managed identities provide an identity for applications to use when connecting to resources that support Microsoft Entra ID authentication. As with any identity, this must be configured correctly, otherwise the identity may be compromised and the malicious actor can gain privileged access.

  • Dive into Managed Identity and JWT tokens
  • Azure resources enumeration
  • Getting access to blob storage, Key Vault and SQL Database using compromised identity

Module 3 – Compute Protection
While companies increasingly use PaaS services, virtual machines are still a common service. There is a growing number of containers and container services like Azure Kubernetes that are not always properly secured.

  • Remote Code Execution in Azure VMs
  • Containers 101
  • Hacking containers in Azure Kubernetes Services
  • Configuring VMs and AKS security

Module 4 – App Service Protection
Using PaaS significantly increases security, but does not relieve the customer of complete responsibility. An incorrectly configured element can cause a critical application to be compromised.

  • Remote Code Execution in Azure App Services
  • Accessing Secrets in Azure Key Vault
  • Securing private Azure SQL Database
Methodology & didactics

This training includes demo-based lectures and hands-on labs

Target audience

Security analysts, security engineers, penetration testers

Requirements

Experience with Azure cloud services as well as Windows and Linux operating systems

Additional information

About the instructor:

Sergey Chubarov is a Security and Cloud Expert, Instructor with 15+ years' experience on Microsoft technologies. His day-to-day job is to help companies securely embrace cloud technologies.

He has certifications and recognitions such as Microsoft MVP: Security, OSCP, OSEP, eCPPT, eCPTX, Microsoft Certified Trainer, MCT Regional Lead, EC Council CEH, CPENT, LPT, CCSE, CEI, CREST CPSA, CRT and more.

Sergey is a frequent speaker at local and international conferences like Global Azure, DEF CON, Black Hat Europe, Wild West Hackin' Fest, Security BSides, Workplace Ninja, Midwest Management Summit, Hack in the Box, Hack in Paris etc. He prefers live demos and cyberattacks simulations.

Download

Questions

Any questions?
First name
Last name
Company optional
Email
Phone
I would like to book this course as a company course
First name
Last name
Company optional
Email
Phone
Number of participants
Desired course location
Start date (DD.MM.YYYY)
End date (DD.MM.YYYY)

Choose your date

28
Apr
2025
29
Apr
2025
Zürich
English
Timetable
CHF 2’100.-
exkl. 8.1% Mwst.
CHF 2’100.-
exkl. 8.1% Mwst.
28
Apr
2025
29
Apr
2025
Berne
English
Timetable
CHF 2’100.-
exkl. 8.1% Mwst.
CHF 2’100.-
exkl. 8.1% Mwst.
28
Apr
2025
29
Apr
2025
Basel
English
Timetable
CHF 2’100.-
exkl. 8.1% Mwst.
CHF 2’100.-
exkl. 8.1% Mwst.
26
Jun
2025
27
Jun
2025
Zürich
English
Timetable
CHF 2’100.-
exkl. 8.1% Mwst.
CHF 2’100.-
exkl. 8.1% Mwst.
26
Jun
2025
27
Jun
2025
Berne
English
Timetable
CHF 2’100.-
exkl. 8.1% Mwst.
CHF 2’100.-
exkl. 8.1% Mwst.
25
Aug
2025
26
Aug
2025
Virtual Training
English
Timetable
CHF 2’100.-
exkl. 8.1% Mwst.
CHF 2’100.-
exkl. 8.1% Mwst.
Next date
28
Apr
2025
29
Apr
2025
Zürich
English
Timetable
CHF 2’100.-
exkl. 8.1% Mwst.
CHF 2’100.-
exkl. 8.1% Mwst.