cloudforge v1.4.0 Azure Key Vault harvest · seed 43

brief

# Lab: `azure_imds_keyvault_harvest`

fintech / enterprise / `azure-payment-gateway` · prod

## Your job

An App Service has a managed identity. Can it reach secrets or customer data that a human operator would not expect it to hold?

For each path, name where it starts, what opens the way, and what the attacker reaches. That is not always data: it can be a role, a key, a secret, an image, a queue, a snapshot or a database.

## Resources

- `n33_82c1/sub-corp-prod`: **AzureSubscription** sub-corp-prod-82c1
- `n41_82c1/rg-workloads`: **AzureResourceGroup** rg-workloads-82c1
- `n18_82c1/app-service-frontend`: **AzureAppService** app-service-frontend-82c1
- `n27_82c1/id-app-service-frontend`: **AzureManagedIdentity** id-app-service-frontend-82c1
- `n03_82c1/kv-corp-secrets`: **AzureKeyVault** kv-corp-secrets-82c1
- `n07_82c1/cnt-customer-financials`: **AzureStorageContainer** cnt-customer-financials-82c1
- `n00_82c1/customer-financials`: **DataSet** customer-financials-82c1
- `n08_82c1/id-migration-helper`: **AzureManagedIdentity** id-migration-helper-82c1
- `n05_82c1/cnt-migration-staging`: **AzureStorageContainer** cnt-migration-staging-82c1
- `n06_82c1/cnt-cdn-origin`: **AzureStorageContainer** cnt-cdn-origin-82c1
- `n45_82c1/cnt-open-data`: **AzureStorageContainer** cnt-open-data-82c1
- `n10_82c1/kv-partner-certs`: **AzureKeyVault** kv-partner-certs-82c1
- `n17_82c1/cnt-partner-contracts`: **AzureStorageContainer** cnt-partner-contracts-82c1
- `n02_82c1/partner-contracts`: **DataSet** partner-contracts-82c1
- `n21_82c1/kv-billing-keys`: **AzureKeyVault** kv-billing-keys-82c1
- `n30_82c1/cnt-billing-statements`: **AzureStorageContainer** cnt-billing-statements-82c1
- `n28_82c1/billing-statements`: **DataSet** billing-statements-82c1
- `n13_82c1/app-internal-wiki`: **AzureAppService** app-internal-wiki-82c1
- `n26_82c1/app-ops-dashboard`: **AzureAppService** app-ops-dashboard-82c1
- `n04_82c1/id-health-probe`: **AzureManagedIdentity** id-health-probe-82c1
- `n14_82c1/rg-sandbox-a`: **AzureResourceGroup** rg-sandbox-a-82c1
- `n24_82c1/cnt-app-logs`: **AzureStorageContainer** cnt-app-logs-82c1
- `n39_82c1/id-monitoring-agent`: **AzureManagedIdentity** id-monitoring-agent-82c1
- `n19_82c1/app-internal-wiki`: **AzureAppService** app-internal-wiki-2-82c1
- `n32_82c1/id-backup-runner`: **AzureManagedIdentity** id-backup-runner-82c1
- `n43_82c1/app-status-page`: **AzureAppService** app-status-page-82c1
- `n40_82c1/cnt-web-logs`: **AzureStorageContainer** cnt-web-logs-82c1
- `n01_82c1/app-internal-wiki`: **AzureAppService** app-internal-wiki-3-82c1
- `n34_82c1/id-metrics-collector`: **AzureManagedIdentity** id-metrics-collector-82c1
- `n38_82c1/app-internal-wiki`: **AzureAppService** app-internal-wiki-4-82c1
- `n35_82c1/kv-build-signing`: **AzureKeyVault** kv-build-signing-82c1
- `n12_82c1/app-release-notes`: **AzureAppService** app-release-notes-82c1
- `n15_82c1/app-internal-wiki`: **AzureAppService** app-internal-wiki-5-82c1
- `n29_82c1/id-monitoring-agent`: **AzureManagedIdentity** id-monitoring-agent-2-82c1
- `n36_82c1/id-backup-runner`: **AzureManagedIdentity** id-backup-runner-2-82c1
- `n09_82c1/cnt-analytics-cache`: **AzureStorageContainer** cnt-analytics-cache-82c1
- `n31_82c1/analytics-cache`: **DataSet** analytics-cache-82c1
- `n37_82c1/cnt-app-logs`: **AzureStorageContainer** cnt-app-logs-2-82c1
- `n44_82c1/cnt-diag-logs`: **AzureStorageContainer** cnt-diag-logs-82c1
- `n16_82c1/cnt-app-logs`: **AzureStorageContainer** cnt-app-logs-3-82c1
- `n22_82c1/id-metrics-collector`: **AzureManagedIdentity** id-metrics-collector-2-82c1
- `n20_82c1/cnt-telemetry-sink`: **AzureStorageContainer** cnt-telemetry-sink-82c1
- `n42_82c1/telemetry-sink`: **DataSet** telemetry-sink-82c1
- `n25_82c1/cnt-func-logs`: **AzureStorageContainer** cnt-func-logs-82c1
- `n11_82c1/cnt-reporting-store`: **AzureStorageContainer** cnt-reporting-store-82c1
- `n23_82c1/reporting-store`: **DataSet** reporting-store-82c1

## Relationships

- `n33_82c1/sub-corp-prod` --organizational_child--> `n41_82c1/rg-workloads`
- `n41_82c1/rg-workloads` --organizational_child--> `n18_82c1/app-service-frontend`
- `n18_82c1/app-service-frontend` --assumes--> `n27_82c1/id-app-service-frontend`
- `n27_82c1/id-app-service-frontend` --can_read--> `n03_82c1/kv-corp-secrets`
- `n03_82c1/kv-corp-secrets` --can_read--> `n07_82c1/cnt-customer-financials`
- `n07_82c1/cnt-customer-financials` --stores_sensitive_data--> `n00_82c1/customer-financials`
- `n08_82c1/id-migration-helper` --can_read--> `n05_82c1/cnt-migration-staging`
- `n10_82c1/kv-partner-certs` --can_read--> `n17_82c1/cnt-partner-contracts`
- `n17_82c1/cnt-partner-contracts` --stores_sensitive_data--> `n02_82c1/partner-contracts`
- `n21_82c1/kv-billing-keys` --can_read--> `n30_82c1/cnt-billing-statements`
- `n30_82c1/cnt-billing-statements` --stores_sensitive_data--> `n28_82c1/billing-statements`
- `n09_82c1/cnt-analytics-cache` --stores_sensitive_data--> `n31_82c1/analytics-cache`
- `n20_82c1/cnt-telemetry-sink` --stores_sensitive_data--> `n42_82c1/telemetry-sink`
- `n11_82c1/cnt-reporting-store` --stores_sensitive_data--> `n23_82c1/reporting-store`

how this works

This estate was prebaked. A unique copy composes on the server in about 20 ms from a scenario spec: 10,000 seeds per family, 15 families. No cloud account was touched; the graph is the source of truth.

The grade is one call to TypeSafe Jev: three yes/no questions (entry, hop, sink) and one depth score (0 to 3, fewer rungs on a short path), typed probabilities back. No grade yet on this page.