microsoft / Azure-Threat-Research-Matrix

MIT License
71 stars 23 forks source link

Added Transitive Role Assignments to Recon phase #9

Closed karimelmel closed 2 years ago

karimelmel commented 2 years ago

During reconnaissance, an actor may abuse the transitive role assignment API to further discover permissions for abuse.

https://learn.microsoft.com/en-us/graph/api/rbacapplication-list-transitiveroleassignments?view=graph-rest-beta