# Lab: `azure_imds_keyvault_harvest` fintech / enterprise / `azure-payment-gateway` · prod ## Your job An App Service has a managed identity. Can it reach secrets or customer data that a human operator would not expect it to hold? For each path, name where it starts, what opens the way, and what the attacker reaches. That is not always data: it can be a role, a key, a secret, an image, a queue, a snapshot or a database. ## Resources - `n33_82c1/sub-corp-prod`: **AzureSubscription** sub-corp-prod-82c1 - `n41_82c1/rg-workloads`: **AzureResourceGroup** rg-workloads-82c1 - `n18_82c1/app-service-frontend`: **AzureAppService** app-service-frontend-82c1 - `n27_82c1/id-app-service-frontend`: **AzureManagedIdentity** id-app-service-frontend-82c1 - `n03_82c1/kv-corp-secrets`: **AzureKeyVault** kv-corp-secrets-82c1 - `n07_82c1/cnt-customer-financials`: **AzureStorageContainer** cnt-customer-financials-82c1 - `n00_82c1/customer-financials`: **DataSet** customer-financials-82c1 - `n08_82c1/id-migration-helper`: **AzureManagedIdentity** id-migration-helper-82c1 - `n05_82c1/cnt-migration-staging`: **AzureStorageContainer** cnt-migration-staging-82c1 - `n06_82c1/cnt-cdn-origin`: **AzureStorageContainer** cnt-cdn-origin-82c1 - `n45_82c1/cnt-open-data`: **AzureStorageContainer** cnt-open-data-82c1 - `n10_82c1/kv-partner-certs`: **AzureKeyVault** kv-partner-certs-82c1 - `n17_82c1/cnt-partner-contracts`: **AzureStorageContainer** cnt-partner-contracts-82c1 - `n02_82c1/partner-contracts`: **DataSet** partner-contracts-82c1 - `n21_82c1/kv-billing-keys`: **AzureKeyVault** kv-billing-keys-82c1 - `n30_82c1/cnt-billing-statements`: **AzureStorageContainer** cnt-billing-statements-82c1 - `n28_82c1/billing-statements`: **DataSet** billing-statements-82c1 - `n13_82c1/app-internal-wiki`: **AzureAppService** app-internal-wiki-82c1 - `n26_82c1/app-ops-dashboard`: **AzureAppService** app-ops-dashboard-82c1 - `n04_82c1/id-health-probe`: **AzureManagedIdentity** id-health-probe-82c1 - `n14_82c1/rg-sandbox-a`: **AzureResourceGroup** rg-sandbox-a-82c1 - `n24_82c1/cnt-app-logs`: **AzureStorageContainer** cnt-app-logs-82c1 - `n39_82c1/id-monitoring-agent`: **AzureManagedIdentity** id-monitoring-agent-82c1 - `n19_82c1/app-internal-wiki`: **AzureAppService** app-internal-wiki-2-82c1 - `n32_82c1/id-backup-runner`: **AzureManagedIdentity** id-backup-runner-82c1 - `n43_82c1/app-status-page`: **AzureAppService** app-status-page-82c1 - `n40_82c1/cnt-web-logs`: **AzureStorageContainer** cnt-web-logs-82c1 - `n01_82c1/app-internal-wiki`: **AzureAppService** app-internal-wiki-3-82c1 - `n34_82c1/id-metrics-collector`: **AzureManagedIdentity** id-metrics-collector-82c1 - `n38_82c1/app-internal-wiki`: **AzureAppService** app-internal-wiki-4-82c1 - `n35_82c1/kv-build-signing`: **AzureKeyVault** kv-build-signing-82c1 - `n12_82c1/app-release-notes`: **AzureAppService** app-release-notes-82c1 - `n15_82c1/app-internal-wiki`: **AzureAppService** app-internal-wiki-5-82c1 - `n29_82c1/id-monitoring-agent`: **AzureManagedIdentity** id-monitoring-agent-2-82c1 - `n36_82c1/id-backup-runner`: **AzureManagedIdentity** id-backup-runner-2-82c1 - `n09_82c1/cnt-analytics-cache`: **AzureStorageContainer** cnt-analytics-cache-82c1 - `n31_82c1/analytics-cache`: **DataSet** analytics-cache-82c1 - `n37_82c1/cnt-app-logs`: **AzureStorageContainer** cnt-app-logs-2-82c1 - `n44_82c1/cnt-diag-logs`: **AzureStorageContainer** cnt-diag-logs-82c1 - `n16_82c1/cnt-app-logs`: **AzureStorageContainer** cnt-app-logs-3-82c1 - `n22_82c1/id-metrics-collector`: **AzureManagedIdentity** id-metrics-collector-2-82c1 - `n20_82c1/cnt-telemetry-sink`: **AzureStorageContainer** cnt-telemetry-sink-82c1 - `n42_82c1/telemetry-sink`: **DataSet** telemetry-sink-82c1 - `n25_82c1/cnt-func-logs`: **AzureStorageContainer** cnt-func-logs-82c1 - `n11_82c1/cnt-reporting-store`: **AzureStorageContainer** cnt-reporting-store-82c1 - `n23_82c1/reporting-store`: **DataSet** reporting-store-82c1 ## Relationships - `n33_82c1/sub-corp-prod` --organizational_child--> `n41_82c1/rg-workloads` - `n41_82c1/rg-workloads` --organizational_child--> `n18_82c1/app-service-frontend` - `n18_82c1/app-service-frontend` --assumes--> `n27_82c1/id-app-service-frontend` - `n27_82c1/id-app-service-frontend` --can_read--> `n03_82c1/kv-corp-secrets` - `n03_82c1/kv-corp-secrets` --can_read--> `n07_82c1/cnt-customer-financials` - `n07_82c1/cnt-customer-financials` --stores_sensitive_data--> `n00_82c1/customer-financials` - `n08_82c1/id-migration-helper` --can_read--> `n05_82c1/cnt-migration-staging` - `n10_82c1/kv-partner-certs` --can_read--> `n17_82c1/cnt-partner-contracts` - `n17_82c1/cnt-partner-contracts` --stores_sensitive_data--> `n02_82c1/partner-contracts` - `n21_82c1/kv-billing-keys` --can_read--> `n30_82c1/cnt-billing-statements` - `n30_82c1/cnt-billing-statements` --stores_sensitive_data--> `n28_82c1/billing-statements` - `n09_82c1/cnt-analytics-cache` --stores_sensitive_data--> `n31_82c1/analytics-cache` - `n20_82c1/cnt-telemetry-sink` --stores_sensitive_data--> `n42_82c1/telemetry-sink` - `n11_82c1/cnt-reporting-store` --stores_sensitive_data--> `n23_82c1/reporting-store`
This estate was prebaked. A unique copy composes on the server in about 20 ms from a scenario spec: 10,000 seeds per family, 15 families. No cloud account was touched; the graph is the source of truth.
The grade is one call to TypeSafe Jev: three yes/no questions (entry, hop, sink) and one depth score (0 to 3, fewer rungs on a short path), typed probabilities back. No grade yet on this page.
cloudforge on GitHub