microsoft / Azure-Threat-Research-Matrix

MIT License
68 stars 23 forks source link

Added Transitive Role Assignments to Recon phase #9

Closed karimelmel closed 1 year ago

karimelmel commented 1 year ago

During reconnaissance, an actor may abuse the transitive role assignment API to further discover permissions for abuse.

https://learn.microsoft.com/en-us/graph/api/rbacapplication-list-transitiveroleassignments?view=graph-rest-beta