Anonymous service identification
Now that we have a basic understanding of Azure infrastructure and the available scopes for an Azure penetration test, let's get started with some practical attacks. In this section, we will cover how we can anonymously identify internet-facing services that are hosted in Azure. Given that many organizations are making use of Azure services, this will be applicable for any external test, regardless of the cloud.
Test at your own risk
For the purposes of this book, we will have some real resources (that the authors are hosting) in the examples that you can use for testing these tools. All the examples in this book, unless noted otherwise, will point to resources that you are authorized to follow the examples with.
Important note
Do not run the tools or examples in this book against systems or services that you do not have authorization to test. Hopefully, we have made this abundantly clear by now.
We will try to call out specific...