Cloud Security Podcast

Cloud Incident Response in Microsoft Azure

Feb 20, 2025
In this engaging discussion, security researcher Katie Knowles, a former Azure incident responder, dives into critical Azure security topics. She unpacks common incident response scenarios and the rising threat of LLM jacking, where attackers misuse authentication tokens. Katie shares insights on privilege escalation in Azure Key Vault and emphasizes the importance of secure role assignments. She also offers practical tips for developing an effective Azure incident response playbook, making Azure's intricate security landscape accessible to all.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

Public Exposure Risks

  • Public exposure of resources remains a significant issue in Azure, often stemming from testing environments with sensitive data.
  • Exposed user sessions or credentials on VMs can grant attackers broad access within Azure.
INSIGHT

Azure Identity Landscape

  • Azure identity includes users, service identities (service principles), managed identities, and application registrations.
  • These identities, coupled with application and resource-specific permissions, create a complex landscape.
ADVICE

Third-Party Identity Management

  • Understand application vs. delegated permissions within Azure, especially concerning third-party apps.
  • Review and manage consent grants for applications to prevent unauthorized access.
Get the Snipd Podcast app to discover more snips from this episode
Get the app