google / cloud-forensics-utils

Python library to carry out DFIR analysis on the Cloud
Apache License 2.0
464 stars 88 forks source link

least privilege permissions? #287

Open juju4 opened 3 years ago

juju4 commented 3 years ago

Testing libcloudforensics in Azure, I set up an app registration https://docs.microsoft.com/en-us/azure/active-directory/develop/quickstart-register-app and try different permissions to operate, one for source, one for dest.

Test was on a unique subscription and CreateDiskCopy action

is it correct assessment? would it be an azure or libcloudforensics limitations?

while ownership at subscription or better resource group level, would be fine for destination, ideally, the minimum set is used for source.

This would be a great addition to documentation https://libcloudforensics.readthedocs.io/en/latest/usermanual/index.html#microsoft-azure