Group Purchasing
Group Purchasing

Detecting Azure Hybrid Machine Attack Paths with Graph Theory

Detecting Azure Hybrid Machine Attack Paths with Graph Theory (PDF, 0.90MB)Published: 07 Jan, 2025
Created by:
Shawn Woods

Today’s on-premises and cloud environments are ever-growing and becoming increasingly complex. Attackers know this and can and will exploit this fact, pivoting from network to network. Identity and access management is more critical than ever with hybrid cloud environments. Proper privileges must be assigned according to least privilege principles; if they are not, this is where the problem starts. Attack path mapping and graph databases offer a solution that can highlight potential paths to compromise.

Through simple Cypher queries, defenders can observe the potential risks within their environments and mitigate them as needed. This research extends the data collected by the security tool BloodHound to uncover hidden connections between on-premises devices and their cloud identities within an Azure environment. The research offers insights into how organizations can utilize standard tools to add context to their attack maps.

Detecting Azure Hybrid Machine Attack Paths with Graph Theory | SANS Institute